CVE-2020-0601: Microsoft Windows CryptoAPI Spoofing Vulnerability
High severity, CVSS 8.1. Actively exploited: in CISA KEV since 2021-11-03. EPSS: 89.4% chance of exploitation in the next 30 days.
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source, aka 'Windows CryptoAPI Spoofing Vulnerability'.
Affected products
- Golang Go: from 1.12, before 1.12.16 (fixed in 1.12.16); from 1.13, before 1.13.7 (fixed in 1.13.7)
- Microsoft Windows 10 1507: affected versions not specified
- Microsoft Windows 10 1607: affected versions not specified
- Microsoft Windows 10 1709: affected versions not specified
- Microsoft Windows 10 1803: affected versions not specified
- Microsoft Windows 10 1809: any version
- Microsoft Windows 10 1903: affected versions not specified
- Microsoft Windows 10 1909: affected versions not specified
- Microsoft Windows Server 1803: affected versions not specified
- Microsoft Windows Server 1903: affected versions not specified
- Microsoft Windows Server 1909: affected versions not specified
- Microsoft Windows Server 2016: affected versions not specified
- Microsoft Windows Server 2019: affected versions not specified
Published 2020-01-14. Last modified 2026-06-17.