目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2020-0601— Microsoft Windows CryptoAPI 信任管理问题漏洞

一分钟漏洞结论

影响对象
Microsoft Windows
利用判断
已确认在野利用,应立即处置
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

Microsoft Windows CryptoAPI是美国微软(Microsoft)公司的一个在Windows 操作系统中添加的密码编译机能。作为资料加密与解密功能的重要基础,CryptoAPI 支持同步,异步的密钥加密处理,以及操作系统中的数字证书 的管理工作。 Microsoft Windows CryptoAPI (Crypt32.dll)中验证椭圆曲线加密(ECC)证书的方法存在信任管理问题漏洞。攻击者可通过使用欺骗性的代码签名证书利用该漏洞签名恶意的可执行文件。以下产品及版本受到影响:Micr

AI 预测 7.5 利用难度: 中等 KEV EPSS 89.44% · P100

公开利用映射 1

ExploitDB · 1 EDB-47933 [local]
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2020-0601 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
N/A
来源: CVE Program / CVE List V5
Vulnerability Description
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source, aka 'Windows CryptoAPI Spoofing Vulnerability'.
来源: CVE Program / CVE List V5
CVSS Information
N/A
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5
Vulnerability Title
Microsoft Windows CryptoAPI 信任管理问题漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Microsoft Windows CryptoAPI是美国微软(Microsoft)公司的一个在Windows 操作系统中添加的密码编译机能。作为资料加密与解密功能的重要基础,CryptoAPI 支持同步,异步的密钥加密处理,以及操作系统中的数字证书 的管理工作。 Microsoft Windows CryptoAPI (Crypt32.dll)中验证椭圆曲线加密(ECC)证书的方法存在信任管理问题漏洞。攻击者可通过使用欺骗性的代码签名证书利用该漏洞签名恶意的可执行文件。以下产品及版本受到影响:Micr
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

神龙十问 — AI 深度分析

十问解析:根本原因、利用方式、修复建议、紧迫性。摘要免费,完整版需登录。

受影响产品

二、漏洞 CVE-2020-0601 的公开POC

# POC 描述 源链接 神龙链接
1 Remote Code Execution Exploit https://github.com/nissan-sudo/CVE-2020-0601 POC详情
2 Zeek package to detect CVE-2020-0601 https://github.com/0xxon/cve-2020-0601 POC详情
3 A Windows Crypto Exploit https://github.com/SherlockSec/CVE-2020-0601 POC详情
4 None https://github.com/JPurrier/CVE-2020-0601 POC详情
5 Zeek package that uses OpenSSL to detect CVE-2020-0601 exploit attempts https://github.com/0xxon/cve-2020-0601-plugin POC详情
6 PoC for CVE-2020-0601- Windows CryptoAPI (Crypt32.dll) https://github.com/ly4k/CurveBall POC详情
7 A PoC for CVE-2020-0601 https://github.com/kudelskisecurity/chainoffools POC详情
8 😂An awesome curated list of repos for CVE-2020-0601. https://github.com/RrUZi/Awesome-CVE-2020-0601 POC详情
9 Curated list of CVE-2020-0601 resources https://github.com/BlueTeamSteve/CVE-2020-0601 POC详情
10 Proof of Concept for CVE-2020-0601 https://github.com/saleemrashid/badecparams POC详情
11 C++ based utility to check if certificates are trying to exploit CVE-2020-0601 https://github.com/0xxon/cve-2020-0601-utils POC详情
12 Powershell to patch CVE-2020-0601 . Complete security rollup for Windows 10 1507-1909 https://github.com/Doug-Moody/Windows10_Cumulative_Updates_PowerShell POC详情
13 None https://github.com/MarkusZehnle/CVE-2020-0601 POC详情
14 CurveBall CVE exploitation https://github.com/YoannDqr/CVE-2020-0601 POC详情
15 Perl version of recently published scripts to build ECC certificates with specific parameters re CVE-2020-0601 https://github.com/thimelp/cve-2020-0601-Perl POC详情
16 Repo containing lua scripts and PCAP to find CVE-2020-0601 exploit attempts via network traffic https://github.com/dlee35/curveball_lua POC详情
17 CurveBall (CVE-2020-0601) - PoC CVE-2020-0601, or commonly referred to as CurveBall, is a vulnerability in which the signature of certificates using elliptic curve cryptography (ECC) is not correctly verified. Attackers can supply hand-rolled generators, bypassing validation, antivirus & all non-protections. https://github.com/IIICTECH/-CVE-2020-0601-ECC---EXPLOIT POC详情
18 None https://github.com/Ash112121/CVE-2020-0601 POC详情
19 CVE-2020-0601 #curveball - Alternative Key Calculator https://github.com/gentilkiwi/curveball POC详情
20 CVE-2020-0601: Windows CryptoAPI Vulnerability. (CurveBall/ChainOfFools) https://github.com/Hans-MartinHannibalLauridsen/CurveBall POC详情
21 PoC for "CurveBall" CVE-2020-0601 https://github.com/apodlosky/PoC_CurveBall POC详情
22 PoC for CVE-2020-0601 - CryptoAPI exploit https://github.com/ioncodes/Curveball POC详情
23 proof of concept for CVE-2020-0601 https://github.com/amlweems/gringotts POC详情
24 PoC for CVE-2020-0601- Windows CryptoAPI (Crypt32.dll) POC: https://github.com/ollypwn/CurveBall https://github.com/yanghaoi/CVE-2020-0601 POC详情
25 Resources related to CurveBall (CVE-2020-0601) detection https://github.com/talbeerysec/CurveBallDetection POC详情
26 PoC for CVE-2020-0601 vulnerability (Code Signing) https://github.com/david4599/CurveballCertTool POC详情
27 这资源是作者复现微软签字证书漏洞CVE-2020-0601,结合相关资源及文章实现。推荐大家结合作者博客,理解ECC算法、Windows验证机制,并尝试自己复现可执行文件签名证书和HTTPS劫持的例子。作为网络安全初学者,自己确实很菜,但希望坚持下去,加油! https://github.com/eastmountyxz/CVE-2020-0601-EXP POC详情
28 这资源是作者复现微软签字证书漏洞CVE-2020-0601,结合相关资源及文章实现。推荐大家结合作者博客,复现了该漏洞和理解恶意软件自启动劫持原理。作为网络安全初学者,自己确实很菜,但希望坚持下去,一起加油! https://github.com/eastmountyxz/CVE-2018-20250-WinRAR POC详情
29 CVE-2020-0601 proof of concept https://github.com/gremwell/cve-2020-0601_poc POC详情
30 Materials for the second Rijeka secuity meetup. We will be discussing Microsoft cryptoapi vulnerability dubbed CurveBall (CVE-2020-0601) https://github.com/bsides-rijeka/meetup-2-curveball POC详情
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2020-0601 的情报信息

登录查看更多情报信息。

CVE-2020-0601 厂商安全公告 (1)

CVE-2020-0601 公开利用代码 (1)

同批安全公告 · Microsoft · 2020-01-14 · 共 49 条

CVE-2020-0639 Microsoft Windows Common Log File System驱动程序信息泄露漏洞
CVE-2020-0642 Microsoft Windows和Microsoft Windows Server 资源管理错误漏洞
CVE-2020-0644 Microsoft Windows和Microsoft Windows Server 安全漏洞
CVE-2020-0651 Microsoft Excel 缓冲区错误漏洞
CVE-2020-0652 Microsoft Office 缓冲区错误漏洞
CVE-2020-0653 Microsoft Excel 缓冲区错误漏洞
CVE-2020-0654 Microsoft OneDrive 安全漏洞
CVE-2020-0656 Microsoft Dynamics 365 跨站脚本漏洞
CVE-2020-0650 Microsoft Excel 缓冲区错误漏洞
CVE-2020-0640 Microsoft Internet Explorer 缓冲区错误漏洞
CVE-2020-0641 Microsoft Windows Media Service 安全漏洞
CVE-2020-0638 Microsoft Update Notification Manager 安全漏洞
CVE-2020-0637 微软 Microsoft Remote Desktop Web Access 信息泄露漏洞
CVE-2020-0636 Microsoft Windows Subsystem for Linux 安全漏洞
CVE-2020-0635 Microsoft Windows和Microsoft Windows Server 安全漏洞
CVE-2020-0634 Microsoft Windows Common Log File System Driver 安全漏洞
CVE-2020-0633 Microsoft Windows Search Indexer 安全漏洞
CVE-2020-0632 Microsoft Windows Search Indexer 安全漏洞
CVE-2020-0631 Microsoft Windows Search Indexer 安全漏洞
CVE-2020-0630 Microsoft Windows Search Indexer 安全漏洞

显示前 20 条,共 49 条。 查看全部 → →

IV. Related Vulnerabilities

V. Comments for CVE-2020-0601

暂无评论


发表评论