LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2020-0601: Microsoft Windows CryptoAPI Spoofing Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2020-0601 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft Windows CryptoAPI (Crypt32.dll) contains a spoofing vulnerability in the way it validates Elliptic Curve Cryptography (ECC) certificates. An attacker could exploit the vulnerability by using…

CVE-2020-0601 is a spoofing vulnerability in Microsoft Windows CryptoAPI (Crypt32.dll) that affects how the system validates Elliptic Curve Cryptography (ECC) certificates. It is also known as CurveBall. An attacker who exploits it can present a spoofed code-signing certificate so that a malicious executable appears to come from a trusted source, or can interfere with encrypted connections. Because CryptoAPI underpins certificate checks across Windows, the issue matters to any organization running affected Windows systems that rely on code signing or TLS trust decisions.

Public detail is limited to the vendor and CISA descriptions; confirm exact product editions, builds, and patch identifiers against the Microsoft advisory before acting.

How it works

The weakness is classified as CWE-295 (Improper Certificate Validation). CryptoAPI fails to validate ECC certificates correctly. An attacker can craft a certificate that the vulnerable validation logic accepts as legitimate even though it is not. With a spoofed code-signing certificate, the attacker can sign malware so that Windows treats the file as coming from a trusted publisher. The same flawed validation can also enable man-in-the-middle attacks against connections that depend on ECC certificates, potentially allowing decryption of confidential information on those connections. Specific exploit mechanics beyond this description are not provided in the given facts and must be confirmed against the vendor advisory.

Am I affected? How to find it in your systems

The vulnerability affects Microsoft Windows components that use CryptoAPI (Crypt32.dll) for ECC certificate validation. This library is present on typical Windows client and server installations that perform code-signing checks, TLS, or other certificate-based trust operations.

How to remediate

Patch first. Apply the updates Microsoft released for this vulnerability exactly as described in the vendor advisory and per CISA’s required action to apply updates per vendor instructions. After patching, verify that Crypt32.dll and related certificate-validation components are at the remediated level on every Windows system in scope.

If you can't patch immediately

Until the vendor update can be deployed, reduce risk with compensating controls suited to improper certificate validation and spoofed code signing.

If your data may have been exposed

Actively exploited certificate-validation flaws can lead to malware execution or interception of confidential data, which in turn can result in broader compromise. Ransomware use is not documented for this CVE in the provided facts. If you suspect exposure, follow your incident-response process: isolate affected hosts, preserve logs, rotate credentials and certificates that may have been observed, and validate the integrity of signed software. You can also run a free exposure scan of your email addresses against known breach data to see whether associated accounts appear in prior breaches while you complete containment and recovery.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
WeaknessCWE-295
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities