CVE-2020-0601: NSA Reported Spoofing Vulnerability in Windows CryptoAPI
by Tenable Security Response Team on January 14, 2020
Microsoft kicks off the first Patch Tuesday of 2020 with the disclosure of CVE-2020-0601, a highly critical flaw in the cryptographic library for Windows.
UPDATE 01/16/2020: This blog post has been updated to reflect the availability of proof-of-concept code for CVE-2020-0601, which is being referred to as CurveBall or Chain of Fools.