← Back to CVE List
Vulnerability Intelligence Report
Microsoft Windows CryptoAPI Spoofing Vulnerability

CVE-2020-0601

A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source, aka 'Windows CryptoAPI Spoofing Vulnerability'.

CISA KEV SSVC: Active Exploitation
CVSS Base Score
8.1
HIGH
Exploitability:2.9
Impact Score:5.2
EPSS Probability:89.44%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-295 ↗CWE-295 Improper Certificate Validation

Affected Products & Versions

Vendor Product Affected Versions
Microsoft Windows 10 Version 1803 for 32-bit Systems (affected), 10 Version 1803 for x64-based Systems (affected), 10 Version 1803 for ARM64-based Systems (affected), 10 Version 1809 for 32-bit Systems (affected), 10 Version 1809 for x64-based Systems (affected), 10 Version 1809 for ARM64-based Systems (affected), 10 Version 1709 for 32-bit Systems (affected), 10 Version 1709 for x64-based Systems (affected), 10 Version 1709 for ARM64-based Systems (affected), 10 for 32-bit Systems (affected), 10 for x64-based Systems (affected), 10 Version 1607 for 32-bit Systems (affected), 10 Version 1607 for x64-based Systems (affected)
Microsoft Windows Server version 1803 (Core Installation) (affected), 2019 (affected), 2019 (Core installation) (affected), 2016 (affected), 2016 (Core installation) (affected)
Microsoft Windows 10 Version 1903 for 32-bit Systems unspecified (affected)
Microsoft Windows 10 Version 1903 for x64-based Systems unspecified (affected)
Microsoft Windows 10 Version 1903 for ARM64-based Systems unspecified (affected)
Microsoft Windows Server, version 1903 (Server Core installation) unspecified (affected)
Microsoft Windows 10 Version 1909 for 32-bit Systems unspecified (affected)
Microsoft Windows 10 Version 1909 for x64-based Systems unspecified (affected)
Microsoft Windows Server, version 1909 (Server Core installation) unspecified (affected)
Microsoft Windows 10 Version 1909 for ARM64-based Systems unspecified (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
89.436%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMicrosoft Corporation · Vendor · USA
Reserved2019-11-04T00:00:00
Published2020-01-14T23:11:20
Last Updated2025-10-21T23:35:53

LINK COPIED TO CLIPBOARD