Feed/CVE-2020-0601
CVE-2020-0601CISA KEV: Actively Exploited

Microsoft Windows CryptoAPI Spoofing Vulnerability

Published Nov 3, 2021·Updated Nov 3, 2021

NVD Description

Microsoft Windows CryptoAPI (Crypt32.dll) contains a spoofing vulnerability in the way it validates Elliptic Curve Cryptography (ECC) certificates. An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source. A successful exploit could also allow the attacker to conduct man-in-the-middle attacks and decrypt confidential information on user connections to the affected software. The vulnerability is also known under the moniker of CurveBall.

Public Exploits & PoCs31 found

PoC: CurveBall

PoC for CVE-2020-0601- Windows CryptoAPI (Crypt32.dll)

876

PoC: chainoffools

A PoC for CVE-2020-0601

340

PoC: curveball

CVE-2020-0601 #curveball - Alternative Key Calculator

72

PoC: badecparams

Proof of Concept for CVE-2020-0601

63

PoC: cve-2020-0601

Zeek package to detect CVE-2020-0601

36

PoC: CVE-2020-0601-EXP

这资源是作者复现微软签字证书漏洞CVE-2020-0601,结合相关资源及文章实现。推荐大家结合作者博客,理解ECC算法、Windows验证机制,并尝试自己复现可执行文件签名证书和HTTPS劫持的例子。作为网络安全初学者,自己确实很菜,但希望坚持下去,加油!

25

PoC: Curveball

PoC for CVE-2020-0601 - CryptoAPI exploit

22

PoC: CurveballCertTool

PoC for CVE-2020-0601 vulnerability (Code Signing)

6

PoC: cve-2020-0601-plugin

Zeek package that uses OpenSSL to detect CVE-2020-0601 exploit attempts

6

PoC: Awesome-CVE-2020-0601

😂An awesome curated list of repos for CVE-2020-0601.

5

PoC: CVE-2020-0601

PoC for CVE-2020-0601- Windows CryptoAPI (Crypt32.dll) POC: https://github.com/ollypwn/CurveBall

3

PoC: -CVE-2020-0601-ECC---EXPLOIT

CurveBall (CVE-2020-0601) - PoC CVE-2020-0601, or commonly referred to as CurveBall, is a vulnerability in which the signature of certificates using elliptic curve cryptography (ECC) is not correctly verified. Attackers can supply hand-rolled generators, bypassing validation, antivirus & all non-protections.

3

PoC: CVE-2020-0601

CurveBall CVE exploitation

3

PoC: CVE-2020-0601

Remote Code Execution Exploit

3

PoC: cve-2020-0601_poc

CVE-2020-0601 proof of concept

2

PoC: CurveBallDetection

Resources related to CurveBall (CVE-2020-0601) detection

2

PoC: CurveBall

CVE-2020-0601: Windows CryptoAPI Vulnerability. (CurveBall/ChainOfFools)

2

PoC: CVE-2020-0601

Curated list of CVE-2020-0601 resources

2

PoC: twoplustwo

Implementing CVE-2020-0601

1

PoC: meetup-2-curveball

Materials for the second Rijeka secuity meetup. We will be discussing Microsoft cryptoapi vulnerability dubbed CurveBall (CVE-2020-0601)

1

PoC: gringotts

proof of concept for CVE-2020-0601

1

PoC: PoC_CurveBall

PoC for "CurveBall" CVE-2020-0601

1

PoC: curveball_lua

Repo containing lua scripts and PCAP to find CVE-2020-0601 exploit attempts via network traffic

1

PoC: cve-2020-0601-Perl

Perl version of recently published scripts to build ECC certificates with specific parameters re CVE-2020-0601

1

PoC: Windows10_Cumulative_Updates_PowerShell

Powershell to patch CVE-2020-0601 . Complete security rollup for Windows 10 1507-1909

1

PoC: cve-2020-0601-utils

C++ based utility to check if certificates are trying to exploit CVE-2020-0601

1

PoC: CVE-2020-0601

A Windows Crypto Exploit

1

PoC: CVE-2020-0601_PoC

Demonstration of CVE-2020-0601 aka curveball. Based on the PoC's available at https://github.com/kudelskisecurity/chainoffools and https://github.com/ly4k/CurveBall

PoC: curveball-plus

simulation experiment of Curveball (CVE-2020-0601) attacks under ECQV implicit certificates with Windows-like verifiers

PoC: -Awesome-CVE-2020-0601-

2017-0021

PoC: CurveballCertTool

PoC for CVE-2020-0601 vulnerability (Code Signing)

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free