{"id":"CVE-2020-0601","vendor_project":"Microsoft","product":"Windows","vulnerability_name":"Microsoft Windows CryptoAPI Spoofing Vulnerability","date_added":"2021-11-03","due_date":"2022-05-03","known_ransomware_use":"Unknown","short_description":"Microsoft Windows CryptoAPI (Crypt32.dll) contains a spoofing vulnerability in the way it validates Elliptic Curve Cryptography (ECC) certificates. An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source. A successful exploit could also allow the attacker to conduct man-in-the-middle attacks and decrypt confidential information on user connections to the affected software. The vulnerability is also known under the moniker of CurveBall.","required_action":"Apply updates per vendor instructions.","cwes":"CWE-295","cvss_version":"3.1","cvss_severity":"HIGH","cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","nvd_published":"2020-01-14","nvd_status":"Analyzed","epss":0.89436,"epss_percentile":0.99778,"cvss_score":8.1,"days_published_to_kev":659,"source":"https://data.cybermax-tools.workers.dev/cve/CVE-2020-0601","by":"CyberMax"}