On January 14, 2020, Microsoft has published a vulnerability in cryptographic libraries (Crypt32.dll) in new versions of Windows in the first Patch Tuesday list of 2020.
On January 14, 2020, Microsoft has published a vulnerability in cryptographic libraries (Crypt32.dll) in new versions of Windows in the first Patch Tuesday list of 2020. The related vulnerability has been reported by the NSA (National Security Agency).
Attackers can use this vulnerability coded CVE-2020-0601 to run malicious software digitally signed by an insecure source as a trusted application. At this point, attackers can skip this control mechanism by spoofing the Crypto32.dll library.
With the successful use of this vulnerability, MITM (Man in the Middle) attacks can be performed to the targeted application, and encrypted data can be opened and read.
SOLUTION/RECOMMENDATION
Security updates published by Microsoft; It must be implemented urgently on all relevant servers before any security incident occurs. Using vulnerability detection systems, all systems should be scanned for this vulnerability and the detected servers should be improved as soon as possible. In addition, if possible, it will be useful to activate signatures related to this vulnerability in security devices.
Before moving on to all systems, it is recommended that the update must be tested to avoid any interruptions over the service.
Operating Systems
Versions
CVE / CWE
CVE-2020-0601
Additional Information
21/07/2021
26/05/2021
14/04/2021
03/03/2021
19/02/2021
20/01/2021
28/12/2020
22/12/2020
07/07/2020
11/03/2020
28/02/2020
+90 216 504 53 30
+90 216 504 53 32
info@barikat.com.tr
Aydınevler Mahallesi,İsmet İnönü Cadddesi,Küçükyalı Ofis Park A Blok,No:20/1 Maltepe İstanbul
+90 312 235 44 41
+90 312 235 44 51
Mustafa Kemal Mahallesi, Dumlupınar Bulvarı No:164, Kentpark Ofis, Kat:4 Daire:06 Çankaya, 06510 Ankara, Turkey
info@barikatbv.com
Millenium Tower Floor 29, Radarweg 29 1045 XN Amsterdam, Netherlands
You can register to our newsletter on the home page to be instantly informed about security vulnerabilities.
© 2021 Barikat Cyber Security All rights reserved.