Description
This detection identifies exploitation attempts targeting CVE-2020-0601, which has a HIGH severity rating. A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates. A cyberattacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source, aka 'Windows CryptoAPI Spoofing Vulnerability'.
Stats
- First seen
- January 2022
- Last seen
- September 2026
CVEs
Alert name variants
| Alert Name |
|---|
| Binary.Exploit.CVE-2020-0601 |
| Exploit.CVE-2020-0601.Gen.1 |
| Exploit.CVE-2020-0601.Gen.2 |
| Win32.Exploit.CVE-2020-0601 |
| Win64.Exploit.CVE-2020-0601 |
