Guru3D.com
  • HOME
  • NEWS
    • Channels
    • Archive
  • DOWNLOADS
    • New Downloads
    • Categories
    • Archive
  • GAME REVIEWS
  • ARTICLES
    • Rig of the Month
    • Join ROTM
    • PC Buyers Guide
    • Guru3D VGA Charts
    • Editorials
    • Dated content
  • HARDWARE REVIEWS
    • Videocards
    • Processors
    • Audio
    • Motherboards
    • Memory and Flash
    • SSD Storage
    • Chassis
    • Media Players
    • Power Supply
    • Laptop and Mobile
    • Smartphone
    • Networking
    • Keyboard Mouse
    • Cooling
    • Search articles
    • Knowledgebase
    • More Categories
  • FORUMS
  • NEWSLETTER
  • CONTACT

New Reviews
G.Skill TridentZ5 RGB DDR5 7200 CL34 2x16 GB review
ASUS TUF Gaming B760-PLUS WIFI D4 review
Netac NV7000 2 TB NVMe SSD Review
ASUS GeForce RTX 4080 Noctua OC Edition review
MSI Clutch GM51 Wireless mouse review
ASUS ROG STRIX B760-F Gaming WIFI review
Asus ROG Harpe Ace Aim Lab Edition mouse review
SteelSeries Arctis Nova Pro Headset review
Ryzen 7800X3D preview - 7950X3D One CCD Disabled
MSI VIGOR GK71 SONIC Blue keyboard review

New Downloads
Intel ARC graphics Driver Download Version: 31.0.101.4257
CrystalDiskInfo 9.0.0 Beta4 Download
AIDA64 Download Version 6.88
GeForce 531.41 WHQL driver download
AMD Radeon Software Adrenalin 23.3.2 WHQL download
GeForce 531.29 WHQL driver download
AMD Ryzen Master Utility Download 2.10.2.2367
AMD Radeon Software Adrenalin 23.3.1 WHQL download
Display Driver Uninstaller Download version 18.0.6.1
CPU-Z download v2.05


New Forum Topics
Windows: Line-Based vs. Message Signaled-Based Interrupts. MSI tool. Forza Horizon 5 Receives NVIDIA DLSS 3 and Reflex Update, Boosting Gameplay Experience Windows power plan settings explorer utility The Last of Us Part I PC Port Receives 77% negative ratings on Steam, due to poor optimization Fine Utilise Power of RadeonPRO Software & SweetFX Part 2 Valve to Discontinue Support for Windows 7, 8, and 8.1 on Steam Starting 2024 Amernime Zone AMD Software: Adrenalin / Pro Driver - Release Discovery 22.12.2 WHQL Windows 12 - News, rumors, info, etc. Intel LGA 7529 Processors are Nearly 10cm in Length AMD Software: Adrenalin Edition 22.40.43.05 for The Last of Us™ Part 1 Release Notes




Guru3D.com » News » Microsoft patches crypt32.dll vulnerability that allows certificate spoofing

Microsoft patches crypt32.dll vulnerability that allows certificate spoofing

by Hilbert Hagedoorn on: 01/15/2020 09:39 AM | source: krebs | 18 comment(s)
Microsoft patches crypt32.dll vulnerability that allows certificate spoofing

Yesterday we shared news about a big potential vulnerability with a Microsoft Windows component known as crypt32.dll, a Windows module that Microsoft says handles “certificate and cryptographic messaging functions. You should have received a patch update, and now the specifics are shared.

Microsoft on Tuesday rolled out an important security fix after the U.S. National Security Agency tipped off the company to a serious flaw in its widely used Windows operating system.

The patch closes a really serious leak in Windows allowing allows attackers to spoof digital certificates. By exploiting that, encrypted communication can be intercepted or a man-in-the-middle attack can be performed. Crypt32.dll is a component within Windows that validates certificates. The vulnerability in Crypt32.dll makes it possible to spoof Elliptic Curve Cryptography, or ECC certificates. Windows creates such ECC certificates, among other things, when handling https traffic.

The patches address the vulnerability CVE-2020-0601 in the usermode cryptographic library, CRYPT32.DLL, that affects Windows 10, Windows Seerver 2016 and Server 2019 systems. The vulnerability exists in the way Windows CryptoAPI validates Elliptic Curve Cryptography (ECC) certificates. This vulnerability is classed "Important" and Microsoft says it has not seen it used in active attacks. An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source. The user would have no way of knowing the file was malicious, because the digital signature would appear to be from a trusted provider. Microsoft has released updates for this flaw (CVE-2020-0601). Their advisory is here. The NSA’s writeup (PDF) includes quite a bit more detail, as does the advisory from CERT.

Microsoft classifies the update as "Important" and recommends that companies install it as quickly as possible. The NSA shared the same sentiment. "The consequences of not patching this vulnerability are large and widespread," writes the intelligence service in a description. "Tools that can exploit this from a distance are likely to be created and distributed quickly."

Please make sure you hit that Windows update button today.







« EEC website is listing Radeon RX 5800 XT, RX 5950, and RX 5950 XT · Microsoft patches crypt32.dll vulnerability that allows certificate spoofing · Epic Games Store has more than 100M users »

Related Stories

Rumor: Microsoft might share information on extremely critical vulnerability later today - 01/14/2020 03:53 PM
It's tagged as a rumor, but you can rest assured it'll become a fact. Keep an eye out on your Tuesday patches, and apply them. According to Krebs On Security, Microsoft is about to release an extre...

Promo: URCDKey Sale: Get Microsoft Office 2016 for $29.82 - 01/10/2020 11:11 AM
URCDKey is a license sites available for various platforms, whether for software or games. This time URCDKeys brings an offer at a competitive price, Microsoft Windows 10 Pro OEM and Office 2016 combo...

Microsoft shows several images of the Xbox Series X AMD SoC - 01/08/2020 10:27 AM
You can always tell it is an AMD chip by that metal side plating eh? Through their Twitter accounts, David Prien, Xbox Senior Hardware Director, and Xbox Head himself, Phil Spencer, revealed two imag...

Microsoft Flight Simulator - Snow Gameplay - 01/03/2020 09:16 AM
Asobo Studio shared a new Microsoft Flight Simulator gameplay video which shows snow environments. The simularor looks just spectacular.   ...

Microsoft at it again, advertising Gmail in Windows 10 Mail points to Outlook - 12/17/2019 11:28 AM
Perhaps you already have noticed it, Microsoft has started select advertising in the Windows suite. For example, in your Windows 10 mail app, you'll now see 'Get Gmail on your phone'. As if that by...


4 pages 1 2 3 4


sverek



Posts: 6070
Joined: 2011-01-02

#5750894 Posted on: 01/15/2020 11:05 AM
I also wonder how the NSA discovered that... what certs they had rigged and suffered from it.
And, iirc, that lately there's been rigged certs for update programs of large companies (Asus?), rigged certs for "security" software (Avira?).
NSA: hey M$ remember the backdoor we asked you to open?
M$: yeah
NSA: close it, we found better one
M$: oh... ok

Mundosold
Senior Member



Posts: 243
Joined: 2012-10-04

#5750914 Posted on: 01/15/2020 12:29 PM
This might be the nastiest security hole in 15+ years. Even specter/meltdown weren't this bad in terms of real world exploit potential.

Astyanax
Senior Member



Posts: 15384
Joined: 2018-03-21

#5750925 Posted on: 01/15/2020 12:48 PM
This might be the nastiest security hole in 15+ years. Even specter/meltdown weren't this bad in terms of real world exploit potential.


it covered a specific certificate chain which is not widely used.

mbk1969
Senior Member



Posts: 13718
Joined: 2013-01-17

#5750929 Posted on: 01/15/2020 12:57 PM
Microsoft to Intel: Learn how to make vulnerabilities - more than 20 years and not a single scandal.

Zooke
Senior Member



Posts: 518
Joined: 2016-09-21

#5750943 Posted on: 01/15/2020 01:36 PM
NSA: hey M$ remember the backdoor we asked you to open?
M$: yeah
NSA: close it, we found better one
M$: oh... ok

I think the conversation went more along the lines of
NSA Mr X: Holy Shit, has found out about the certificate exploit we have been using for years.
NSA Boss: Damn, let MS know, tell them we only discovered it yesterday. Tell them to publicly thank us too, make people think we have done it for their safety .
NSA Mr X: Spy on everyone for years and still come out of it smelling of roses, that's why you're the boss, Boss.

4 pages 1 2 3 4


Post New Comment
Click here to post a comment for this news story on the message forum.


Guru3D.com © 2023