Lucene search

K
osvGoogleOSV:CVE-2020-0601
HistoryJan 14, 2020 - 11:15 p.m.

CVE-2020-0601

2020-01-1423:15:30
Google
osv.dev
8

AI Score

6.5

Confidence

Low

EPSS

0.97

Percentile

99.8%

A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source, aka β€˜Windows CryptoAPI Spoofing Vulnerability’.