Microsoft Patches Critical Windows Crypto Flaw Flagged by the NSA
Microsoft's January 2020 Patch Tuesday addresses 49 vulnerabilities, headlined by a critical Windows CryptoAPI flaw disclosed by the NSA. Experts urge immediate patching due to the unprecedented nature of the government's public warning.
Microsoft releases a relatively light batch of security updates for January 2020 Patch Tuesday, fixing 49 vulnerabilities across Windows, Office, and other products. Eight of these flaws receive a critical rating, though Microsoft reports that none are currently under active attack. The update stands out because it addresses a highly significant Windows CryptoAPI vulnerability that the NSA publicly flags instead of keeping secret for intelligence purposes.
The standout flaw, tracked as CVE-2020-0601, allows attackers to spoof code-signing certificates to sign malicious executables or to intercept and alter encrypted communications. This bug specifically impacts the validation of Elliptic Curve Cryptography (ECC) certificates within the Windows Crypt32.dll file and affects newer versions of Windows and Windows Server. Security experts emphasize that this public disclosure by a U.S. intelligence agency is exceptionally rare and highlights the severe risk the flaw poses to critical infrastructure.
Industry leaders note that Microsoft provides the fix in advance to the U.S. government and critical infrastructure operators, marking a notable shift from standard practices. While the exact timeline of the vulnerability's discovery remains unknown, security professionals urge all organizations to prioritize installing this patch immediately. Addressing this crypto flaw effectively neutralizes the threat of certificate spoofing and restores secure validation processes for Windows systems.