Microsoft released the Patch Tuesday January 2020 yesterday, which fixes 49 vulnerabilities . One of the most critical vulnerabilities being fixed is a crypto bug , which affects the Windows operating system .
The security was discovered by the National Security Agency US (NSA), which informed Microsoft.
CVE-2020-0601
The vulnerability has been named CVE-2020-0601 and affects Windows CryptoAPI. CryptoAPI is a core component of Windows.
This is a spoofing vulnerability that affects the way the Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.
According to Microsoft, an attacker could exploit the vulnerability to create a malicious executable and make it appear as if it came from a legitimate source.
It could also be used to forge digital certificates used for encrypted communications.
Finally, Microsoft warned that malicious hackers could exploit the vulnerability to carry out man-in-the-middle attacks and decrypt confidential information.
The company said that this particular bug affects Windows 10, Windows Server 2019 and Windows Server 2016.
The good news is that no exploits have been discovered. Those who don't want to fall victim to an attack should install the patch immediately.

The vulnerability is very serious. The NSA said it informed Microsoft about the security issue and did not use it for tools and operations.
Many cybersecurity organizations have previously reported significant vulnerabilities to Microsoft.
Microsoft thanks the NSA for its help, as this is the first time it has reported the existence of a bug.
The organization also published some security tips and ways to detect the exploit and encouraged all users and IT professionals to install the January patch as soon as possible.
