A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source, aka 'Windows CryptoAPI Spoofing Vulnerability'.
Se presenta una vulnerabilidad de suplantación de identidad en la manera en que Windows CryptoAPI (Crypt32.dll) comprueba los certificados Elliptic Curve Cryptography (ECC). Un atacante podría explotar la vulnerabilidad mediante el uso de un certificado de firma de código falsificado para firmar un ejecutable malicioso, haciendo que parezca que el archivo era de una fuente confiable y legítima, también se conoce como "Windows CryptoAPI Spoofing Vulnerability".
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | NONE |
| User Interaction | REQUIRED |
| Scope | UNCHANGED |
| Confidentiality Impact | HIGH |
| Integrity Impact | HIGH |
| Availability Impact | NONE |
AV:N/AC:M/Au:N/C:P/I:P/A:N
| Access Vector | NETWORK |
|---|---|
| Access Complexity | MEDIUM |
| Authentication | NONE |
| Confidentiality Impact | PARTIAL |
| Integrity Impact | PARTIAL |
| Availability Impact | NONE |
| Source | Type | Description |
|---|---|---|
| [email protected] | Primary |
en
CWE-295
|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | Secondary |
en
CWE-295
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| microsoft | windows_10_1507 | - | <built-in method update of dict object at 0x7e60eb227840> | Operating System |
| microsoft | windows_10_1507 | - | <built-in method update of dict object at 0x7e60a88ad680> | Operating System |
| microsoft | windows_10_1607 | - | <built-in method update of dict object at 0x7e61342d2800> | Operating System |
| microsoft | windows_10_1607 | - | <built-in method update of dict object at 0x7e6108407580> | Operating System |
| microsoft | windows_10_1709 | - | <built-in method update of dict object at 0x7e60eb227380> | Operating System |
| microsoft | windows_10_1709 | - | <built-in method update of dict object at 0x7e60eb225740> | Operating System |
| microsoft | windows_10_1709 | - | <built-in method update of dict object at 0x7e60eb225e80> | Operating System |
| microsoft | windows_10_1803 | - | <built-in method update of dict object at 0x7e61114e2f80> | Operating System |
| microsoft | windows_10_1803 | - | <built-in method update of dict object at 0x7e61084057c0> | Operating System |
| microsoft | windows_10_1803 | - | <built-in method update of dict object at 0x7e60eb225980> | Operating System |
| microsoft | windows_10_1809 | * | <built-in method update of dict object at 0x7e60eb226000> | Operating System |
| microsoft | windows_10_1809 | * | <built-in method update of dict object at 0x7e613c3519c0> | Operating System |
| microsoft | windows_10_1809 | * | <built-in method update of dict object at 0x7e60eb225240> | Operating System |
| microsoft | windows_10_1903 | - | <built-in method update of dict object at 0x7e60eb225dc0> | Operating System |
| microsoft | windows_10_1903 | - | <built-in method update of dict object at 0x7e60eb226640> | Operating System |
| microsoft | windows_10_1903 | - | <built-in method update of dict object at 0x7e60eb224600> | Operating System |
| microsoft | windows_10_1909 | - | <built-in method update of dict object at 0x7e6108406680> | Operating System |
| microsoft | windows_10_1909 | - | <built-in method update of dict object at 0x7e6108406ac0> | Operating System |
| microsoft | windows_10_1909 | - | <built-in method update of dict object at 0x7e6108405240> | Operating System |
| microsoft | windows_server_1803 | - | <built-in method update of dict object at 0x7e60a88aeb40> | Operating System |
| microsoft | windows_server_1903 | - | <built-in method update of dict object at 0x7e60eb225780> | Operating System |
| microsoft | windows_server_1909 | - | <built-in method update of dict object at 0x7e60a88ac280> | Operating System |
| microsoft | windows_server_2016 | - | <built-in method update of dict object at 0x7e6108406840> | Operating System |
| microsoft | windows_server_2019 | - | <built-in method update of dict object at 0x7e60a88afa40> | Operating System |
| golang | go | * | <built-in method update of dict object at 0x7e60a88adb40> | Application |
| golang | go | * | <built-in method update of dict object at 0x7e60a88ac740> | Application |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:microsoft:windows_10_1507:-:*:*:*:*:*:x64:* |
| Yes | cpe:2.3:o:microsoft:windows_10_1507:-:*:*:*:*:*:x86:* |
| Yes | cpe:2.3:o:microsoft:windows_10_1607:-:*:*:*:*:*:x64:* |
| Yes | cpe:2.3:o:microsoft:windows_10_1607:-:*:*:*:*:*:x86:* |
| Yes | cpe:2.3:o:microsoft:windows_10_1709:-:*:*:*:*:*:arm64:* |
| Yes | cpe:2.3:o:microsoft:windows_10_1709:-:*:*:*:*:*:x64:* |
| Yes | cpe:2.3:o:microsoft:windows_10_1709:-:*:*:*:*:*:x86:* |
| Yes | cpe:2.3:o:microsoft:windows_10_1803:-:*:*:*:*:*:arm64:* |
| Yes | cpe:2.3:o:microsoft:windows_10_1803:-:*:*:*:*:*:x64:* |
| Yes | cpe:2.3:o:microsoft:windows_10_1803:-:*:*:*:*:*:x86:* |
| Yes | cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:arm64:* |
| Yes | cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:* |
| Yes | cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:* |
| Yes | cpe:2.3:o:microsoft:windows_10_1903:-:*:*:*:*:*:arm64:* |
| Yes | cpe:2.3:o:microsoft:windows_10_1903:-:*:*:*:*:*:x64:* |
| Yes | cpe:2.3:o:microsoft:windows_10_1903:-:*:*:*:*:*:x86:* |
| Yes | cpe:2.3:o:microsoft:windows_10_1909:-:*:*:*:*:*:arm64:* |
| Yes | cpe:2.3:o:microsoft:windows_10_1909:-:*:*:*:*:*:x64:* |
| Yes | cpe:2.3:o:microsoft:windows_10_1909:-:*:*:*:*:*:x86:* |
| Yes | cpe:2.3:o:microsoft:windows_server_1803:-:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:microsoft:windows_server_1903:-:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:microsoft:windows_server_1909:-:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:microsoft:windows_server_2019:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:golang:go:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:golang:go:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |