A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source, aka 'Windows CryptoAPI Spoofing Vulnerability'.
2020-01-14T23:15:30.207
2025-04-10T16:54:50.000
Analyzed
CVSSv3.1: 8.1 (HIGH)
AV:N/AC:M/Au:N/C:P/I:P/A:N
8.6
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | microsoft | windows_10_1507 | - | Yes |
Operating System | microsoft | windows_10_1507 | - | Yes |
Operating System | microsoft | windows_10_1607 | - | Yes |
Operating System | microsoft | windows_10_1607 | - | Yes |
Operating System | microsoft | windows_10_1709 | - | Yes |
Operating System | microsoft | windows_10_1709 | - | Yes |
Operating System | microsoft | windows_10_1709 | - | Yes |
Operating System | microsoft | windows_10_1803 | - | Yes |
Operating System | microsoft | windows_10_1803 | - | Yes |
Operating System | microsoft | windows_10_1803 | - | Yes |
Operating System | microsoft | windows_10_1809 | * | Yes |
Operating System | microsoft | windows_10_1809 | * | Yes |
Operating System | microsoft | windows_10_1809 | * | Yes |
Operating System | microsoft | windows_10_1903 | - | Yes |
Operating System | microsoft | windows_10_1903 | - | Yes |
Operating System | microsoft | windows_10_1903 | - | Yes |
Operating System | microsoft | windows_10_1909 | - | Yes |
Operating System | microsoft | windows_10_1909 | - | Yes |
Operating System | microsoft | windows_10_1909 | - | Yes |
Operating System | microsoft | windows_server_1803 | - | Yes |
Operating System | microsoft | windows_server_1903 | - | Yes |
Operating System | microsoft | windows_server_1909 | - | Yes |
Operating System | microsoft | windows_server_2016 | - | Yes |
Operating System | microsoft | windows_server_2019 | - | Yes |
Application | golang | go | < 1.12.16 | Yes |
Application | golang | go | < 1.13.7 | Yes |
Operating System | microsoft | windows | - | No |