CVE-2020-0601

Description

A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source, aka Windows CryptoAPI Spoofing Vulnerability.

Risk Information

Base Score
8.0
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N/E:P/RL:O/RC:C
EPSS Score
Exploitation Probability
94.093

Associated Vulnerability

VulnerabilityOS Platform
Windows Search Indexer Elevation of Privilege Vulnerability for Windows 10 Version 1507 for x64-based Systems (KB4534306)Windows
Windows Search Indexer Elevation of Privilege Vulnerability for Windows 10 Version 1507 for x86-based Systems (KB4534306)Windows
Windows Search Indexer Elevation of Privilege Vulnerability for Windows 10 Version 1903 for x86-based Systems (KB4528760)Windows
Windows Search Indexer Elevation of Privilege Vulnerability for Windows 10 Version 1903 for x64-based Systems (KB4528760)Windows
Windows Search Indexer Elevation of Privilege Vulnerability for Windows 10 Version 1909 for x86-based Systems (KB4528760)Windows
Windows Search Indexer Elevation of Privilege Vulnerability for Windows 10 Version 1909 for x64-based Systems (KB4528760)Windows
Windows Search Indexer Elevation of Privilege Vulnerability for Windows Server, version 1909 for x64-based Systems (KB4528760)Windows
Windows Search Indexer Elevation of Privilege Vulnerability for Windows Server, version 1903 for x64-based Systems (KB4528760)Windows
Windows Search Indexer Elevation of Privilege Vulnerability for Windows 10 Version 1803 for x64-based Systems (KB4534293)Windows
Windows Search Indexer Elevation of Privilege Vulnerability for Windows Server 2016 (1803) for x64-based Systems (KB4534293)Windows
Windows Search Indexer Elevation of Privilege Vulnerability for Windows 10 Version 1803 for x86-based Systems (KB4534293)Windows
Windows Search Indexer Elevation of Privilege Vulnerability for Windows Server 2019 for x64-based Systems (KB4534273)Windows
Windows Search Indexer Elevation of Privilege Vulnerability for Windows 10 Version 1809 for x64-based Systems (KB4534273)Windows
Windows Search Indexer Elevation of Privilege Vulnerability for Windows 10 Version 1809 for x86-based Systems (KB4534273)Windows
Windows Search Indexer Elevation of Privilege Vulnerability for Windows 10 Version 1709 for x86-based Systems (KB4534276)Windows
Windows Search Indexer Elevation of Privilege Vulnerability for Windows 10 Version 1709 for x64-based Systems (KB4534276)Windows
Windows Search Indexer Elevation of Privilege Vulnerability for Windows 10 Version 1607 for x64-based Systems (KB4534271)Windows
Windows Search Indexer Elevation of Privilege Vulnerability for Windows 10 Version 1607 for x86-based Systems (KB4534271)Windows
Windows Search Indexer Elevation of Privilege Vulnerability for Windows Server 2016 for x64-based Systems (KB4534271)Windows
Vulnerabilities CVE-2020-6378,CVE-2020-6379,CVE-2020-6380,CVE-2020-0601 are fixed in Google Chrome (x64) (79.0.3945.130)Windows
Vulnerabilities CVE-2020-6378,CVE-2020-6379,CVE-2020-6380,CVE-2020-0601 are fixed in Google Chrome (79.0.3945.130)Windows
Vulnerabilities CVE-2020-6378, CVE-2020-6379, CVE-2020-6380, CVE-2020-0601 are fixed in Microsoft Edge for business (x64) 79.0.309.68Windows
Vulnerabilities CVE-2020-6378, CVE-2020-6379, CVE-2020-6380, CVE-2020-0601 are fixed in Microsoft Edge for business 79.0.309.68Windows
Multiple vulnerabilities fixed in Microsoft Edge for business 79.0.309.68Windows
Vulnerabilities CVE-2020-6378,CVE-2020-6379,CVE-2020-6380,CVE-2020-0601 are fixed in Google Chrome (79.0.3945.130) (For Debian)Linux
Vulnerabilities CVE-2020-6378,CVE-2020-6379,CVE-2020-6380,CVE-2020-0601 are fixed in Google Chrome (79.0.3945.130) (For Centos)Linux
Vulnerabilities CVE-2020-6378,CVE-2020-6379,CVE-2020-6380,CVE-2020-0601 are fixed in Google Chrome (79.0.3945.130) (For RedHat)Linux
Vulnerabilities CVE-2020-6378,CVE-2020-6379,CVE-2020-6380,CVE-2020-0601 are fixed in Google Chrome (79.0.3945.130) (For Suse)Linux
Vulnerabilities CVE-2020-6378,CVE-2020-6379,CVE-2020-6380,CVE-2020-0601 are fixed in Google Chrome (79.0.3945.130) (For Ubuntu)Linux

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-281402020-01 Cumulative Update for Windows 10 Version 1507 for x64-based Systems (KB4534306)
PATCH-281412020-01 Cumulative Update for Windows 10 Version 1507 for x86-based Systems (KB4534306)
PATCH-281552020-01 Cumulative Update for Windows 10 Version 1903 for x86-based Systems (KB4528760)
PATCH-281562020-01 Cumulative Update for Windows 10 Version 1903 for x64-based Systems (KB4528760)
PATCH-281572020-01 Cumulative Update for Windows 10 Version 1909 for x86-based Systems (KB4528760)
PATCH-281582020-01 Cumulative Update for Windows 10 Version 1909 for x64-based Systems (KB4528760)
PATCH-281592020-01 Cumulative Update for Windows Server, version 1909 for x64-based Systems (KB4528760)
PATCH-281602020-01 Cumulative Update for Windows Server, version 1903 for x64-based Systems (KB4528760)
PATCH-281492020-01 Cumulative Update for Windows 10 Version 1803 for x64-based Systems (KB4534293)
PATCH-281502020-01 Cumulative Update for Windows Server 2016 (1803) for x64-based Systems (KB4534293)
PATCH-281512020-01 Cumulative Update for Windows 10 Version 1803 for x86-based Systems (KB4534293)
PATCH-281522020-01 Cumulative Update for Windows Server 2019 for x64-based Systems (KB4534273)
PATCH-281532020-01 Cumulative Update for Windows 10 Version 1809 for x64-based Systems (KB4534273)
PATCH-281542020-01 Cumulative Update for Windows 10 Version 1809 for x86-based Systems (KB4534273)
PATCH-281472020-01 Cumulative Update for Windows 10 Version 1709 for x86-based Systems (KB4534276)
PATCH-281482020-01 Cumulative Update for Windows 10 Version 1709 for x64-based Systems (KB4534276)
PATCH-281422020-01 Cumulative Update for Windows 10 Version 1607 for x64-based Systems (KB4534271)
PATCH-281432020-01 Cumulative Update for Windows 10 Version 1607 for x86-based Systems (KB4534271)
PATCH-281442020-01 Cumulative Update for Windows Server 2016 for x64-based Systems (KB4534271)
PATCH-312542Google Chrome (x64) (79.0.3945.130)
PATCH-312541Google Chrome (79.0.3945.130)
PATCH-109332Microsoft Edge for chromium business (99.0.1150.30) (x64)
PATCH-109333Microsoft Edge for chromium business (99.0.1150.30) (x86)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234