What CVE-2020-0601 Teaches Us About Microsoft’s TLS Certificate Verification Process
ID: b4480344-aa99-5345-a59a-8b44dcda2cb3
STIX ID: report--b4480344-aa99-5345-a59a-8b44dcda2cb3
Feed Name: McAfee Labs Blog
Threat Score
McAfee researchers detail CVE-2020-0601 (CurveBall), an ECC certificate validation bug in Windows 10 that allowed attackers to craft spoofed CA certificates and have unpatched systems trust malicious binaries and HTTPS servers; McAfee reproduced HTTPS PoCs, identified that Windows compared only public keys (omitting curve parameters) which enabled the spoof, and noted that Microsoft’s patch and McAfee Web Gateway certificate verification protect clients.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
