Skip to main content
CISA Known Exploited Vulnerabilities

Microsoft Windows CryptoAPI Spoofing Vulnerability is confirmed as actively exploited and is listed in the CISA KEV catalog.

Added to KEV
2021-11-03
Remediation due
2022-05-03

Required action
Apply updates per vendor instructions.

CISA notes
Reference CISA's ED 20-02 (https://www.cisa.gov/news-events/directives/ed-20-02-mitigate-windows-vulnerabilities-january-2020-patch-tuesday) for further guidance and requirements. Note: The due date for addressing this vulnerability aligns with the requirements outlined in ED 20-02. https://nvd.nist.gov/vuln/detail/CVE-2020-0601

Description

A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source, aka 'Windows CryptoAPI Spoofing Vulnerability'.

Severity

CVSS 3.1 · CISA8.1 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
SSVC · CISA-ADP
Exploitationactive
Automatableno
Technical impacttotal

Affected Products

VendorProductAffected versions
MicrosoftWindows
10 Version 1803 for 32-bit Systems
10 Version 1803 for x64-based Systems
10 Version 1803 for ARM64-based Systems
10 Version 1809 for 32-bit Systems
10 Version 1809 for x64-based Systems
10 Version 1809 for ARM64-based Systems
10 Version 1709 for 32-bit Systems
10 Version 1709 for x64-based Systems
10 Version 1709 for ARM64-based Systems
10 for 32-bit Systems
10 for x64-based Systems
10 Version 1607 for 32-bit Systems
10 Version 1607 for x64-based Systems
MicrosoftWindows Server
version 1803 (Core Installation)
2019
2019 (Core installation)
2016
2016 (Core installation)
MicrosoftWindows 10 Version 1903 for 32-bit Systems
unspecified
MicrosoftWindows 10 Version 1903 for x64-based Systems
unspecified
MicrosoftWindows 10 Version 1903 for ARM64-based Systems
unspecified
MicrosoftWindows Server, version 1903 (Server Core installation)
unspecified
MicrosoftWindows 10 Version 1909 for 32-bit Systems
unspecified
MicrosoftWindows 10 Version 1909 for x64-based Systems
unspecified
MicrosoftWindows Server, version 1909 (Server Core installation)
unspecified
MicrosoftWindows 10 Version 1909 for ARM64-based Systems
unspecified

CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Exploited-in-the-wild data from the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not endorsed or certified by MITRE, NVD, CISA, or FIRST.