Netskope Threat Labs

CVE-2020-0601

ATP Sandbox Adv. HeuristicsAVNetskope IPS

This detection identifies exploitation attempts targeting CVE-2020-0601, which has a HIGH severity rating. A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates. A cyberattacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source, aka 'Windows CryptoAPI Spoofing Vulnerability'.

First seen
January 2022
Last seen
September 2026
Alert Name
Binary.Exploit.CVE-2020-0601
Exploit.CVE-2020-0601.Gen.1
Exploit.CVE-2020-0601.Gen.2
Win32.Exploit.CVE-2020-0601
Win64.Exploit.CVE-2020-0601