Security researchers today published proof-of-concept (PoC) code to exploit a crypto bug discovered and reported to Microsoft by the NSA. The vulnerability affected Windows, but has now been patched, as Microsoft included it in its January 2020 Patch Tuesday
Some have dubbed the bug "CurveBall", and as we mentioned in a previous article, it affects CryptoAPI (Crypt32.dll), a core Windows component.
Researcher Tal Be'ery analyzed the bug and said that "the cause of this vulnerability is the incorrect implementation of Elliptic Curve Cryptography (ECC) in Microsoft's code."
According to the NSA, DHS access , to sensitive information and Microsoft, exploiting this vulnerability (CVE-2020-0601) could allow an attacker to perform a man-in-the-middle attack, gain , create fake certificates, and more.

Security experts characterize the vulnerability as critical.
This is the first time the NSA has reported the existence of a bug to Microsoft. The authorities gave government agencies to install Microsoft's January 2020 Patch.
Prominent security experts and researchers , such as Thomas Ptacek and Kenneth White, confirmed the severity and broad impact of the vulnerability.
Researchers published proof-of-concept exploits
The first researcher to work on the CurveBall vulnerability was Saleem Rashid, who created proof-of-concept code for forging TLS certificates. This way, sites appear legitimate. Rashid did not publish his code, but other researchers did just a few hours later. The first public CurveBall exploit came from Kudelski Security. A second exploit followed, from a Danish researcher named Ollypwn.
After the release of the exploits, the chances of an attack increase, which is why users should install the new update. The good news, for those who haven't received the patch yet, is that Windows Defender has received updates to detect exploit attempts and warn users.
