HomeSecurityMicrosoft: Fixes Windows crypto bug reported by NSA

Microsoft: Fixes Windows crypto bug reported by NSA

Microsoft released the Patch Tuesday January 2020 yesterday, which fixes 49 vulnerabilities . One of the most critical vulnerabilities being fixed is a crypto bug , which affects the Windows operating system .Microsoft: Fixes Windows crypto bug reported by NSA

The security was discovered by the National Security Agency US (NSA), which informed Microsoft.

CVE-2020-0601

The vulnerability has been named CVE-2020-0601 and affects Windows CryptoAPI. CryptoAPI is a core component of Windows.

This is a spoofing vulnerability that affects the way the Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.

According to Microsoft, an attacker could exploit the vulnerability to create a malicious executable and make it appear as if it came from a legitimate source.

It could also be used to forge digital certificates used for encrypted communications.

Finally, Microsoft warned that malicious hackers could exploit the vulnerability to carry out man-in-the-middle attacks and decrypt confidential information.

The company said that this particular bug affects Windows 10, Windows Server 2019 and Windows Server 2016.

The good news is that no exploits have been discovered. Those who don't want to fall victim to an attack should install the patch immediately.

Microsoft: Fixes Windows crypto bug reported by NSA

The vulnerability is very serious. The NSA said it informed Microsoft about the security issue and did not use it for tools and operations.

Many cybersecurity organizations have previously reported significant vulnerabilities to Microsoft.

Microsoft thanks the NSA for its help, as this is the first time it has reported the existence of a bug.

The organization also published some security tips and ways to detect the exploit and encouraged all users and IT professionals to install the January patch as soon as possible.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS