← Back to browse · API

CVE-2020-0601

Severity
HIGH
CVSS
8.1
EPSS
0.89436
Risk score
56.3
CISA KEV
Yes
PoC
No
Published
2020-01-14
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2020-2099, GHSA-82JC-CV6X-R223
Products
Microsoft:Windows, Microsoft:Windows 10 Version 1607 for 32-bit Systems, Microsoft:Windows 10 Version 1607 for x64-based Systems, Microsoft:Windows 10 Version 1709 for 32-bit Systems, Microsoft:Windows 10 Version 1709 for ARM64-based Systems, Microsoft:Windows 10 Version 1709 for x64-based Systems, Microsoft:Windows 10 Version 1803 for 32-bit Systems, Microsoft:Windows 10 Version 1803 for ARM64-based Systems, Microsoft:Windows 10 Version 1803 for x64-based Systems, Microsoft:Windows 10 Version 1809 for 32-bit Systems, Microsoft:Windows 10 Version 1809 for ARM64-based Systems, Microsoft:Windows 10 Version 1809 for x64-based Systems, Microsoft:Windows 10 Version 1903 for 32-bit Systems unspecified, Microsoft:Windows 10 Version 1903 for ARM64-based Systems unspecified, Microsoft:Windows 10 Version 1903 for x64-based Systems unspecified, Microsoft:Windows 10 Version 1909 for 32-bit Systems unspecified, Microsoft:Windows 10 Version 1909 for ARM64-based Systems unspecified, Microsoft:Windows 10 Version 1909 for x64-based Systems unspecified, Microsoft:Windows 10 for 32-bit Systems, Microsoft:Windows 10 for x64-based Systems, Microsoft:Windows Server 2016, Microsoft:Windows Server 2016 (Core installation), Microsoft:Windows Server 2019, Microsoft:Windows Server 2019 (Core installation), Microsoft:Windows Server version 1803 (Core Installation), Microsoft:Windows Server, version 1903 (Server Core installation) unspecified, Microsoft:Windows Server, version 1909 (Server Core installation) unspecified
Sources
cisa.gov CVE-2020-0601
euvd EUVD-2020-2099

Description

A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source, aka 'Windows CryptoAPI Spoofing Vulnerability'.

References