← Back to CVE List

CVE-2020-0601

Published: 2020-01-14T23:15Z
Last Modified: 2025-04-10T16:54Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source, aka 'Windows CryptoAPI Spoofing Vulnerability'. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt