HomeSecurityWindows CryptoAPI: Vulnerable to attacks due to a serious bug

Windows CryptoAPI: Vulnerable to attacks due to a serious bug

Akamai researchers have published a Proof of Concept of a serious vulnerability in Windows CryptoAPI, originally discovered by the NSA and the UK's NCSC, that allows forgery of certificates with MD5 collisions.

See also: New Python RAT malware targets Windows in attacks

Windows CryptoAPI

Windows CryptoAPI (Crypto API) is a set of application programming interfaces (APIs) that provide cryptographic services to applications running on the Microsoft Windows operating system. It allows developers to integrate encryption and other security measures into their applications. The APIs are designed to be easy to use, so developers can quickly add security features with minimal effort. 

Dubbed CVE-2022-34689, Microsoft released security updates in August 2022 to address this vulnerability, however, it was not until October that the company publicly announced the issue with a published advisory.

As describes , a malicious attacker could use an existing public x.509 to disguise their identity and complete activities such as authentication or code signing under the name of the targeted certificate.

This vulnerability, which has been rated as critical by the company, can be easily exploited by unauthorized attackers.

See also: Microsoft stops selling Windows 10 licenses

error

In its latest effort, cloud security firm Akamai created a proof of concept (PoC) exploit and built an OSQuery to help identify versions of the CryptoAPI library that are vulnerable to malicious attacks.

By exploiting this vulnerability, malicious actors can disrupt trust verification for HTTPS connections and signed executables, emails, or files.

For example, malicious actors can exploit this vulnerability to sign malicious executable files with a fake code signing certificate, making the file appear as if it came from an authentic source.

As a result, targets will not know that this file is malicious, as they will assume that the digital signature comes from an authentic and trusted source.

See also: Run Command Prompt as administrator in Windows 11 and 10

A successful attack using the CVE-2022-34689 exploit could give malicious actors control over users' connections and even decrypt their confidential data , such as that of web browsers that use the Windows CryptoAPI encryption library. This type of attack is known as a man-in-the-middle attack , which can be incredibly dangerous if not prevented in time.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS