NSA Discovers Critical Windows Crypto Spoofing Flaw Patched by Microsoft

Microsoft addresses a severe Windows CryptoAPI vulnerability discovered by the NSA that allows attackers to spoof digital certificates. Government agencies strongly urge immediate patching to prevent malicious code from appearing trusted.

Microsoft patches a critical spoofing vulnerability in the Windows CryptoAPI library (Crypt32.dll) that affects Windows 10, Windows Server 2016, and Windows Server 2019 systems. The National Security Agency (NSA) discovers this flaw and immediately reports it to Microsoft, warning that attackers exploit it to defeat trusted network connections and deliver malicious code disguised as legitimate software.

This vulnerability allows attackers to spoof Elliptic Curve Cryptography (ECC) certificate chains by using forged code-signing certificates on malicious executables. Because the digital signature appears to come from a trusted provider, users have no way of knowing the file is harmful. Additionally, attackers use this exploit to launch man-in-the-middle attacks and decrypt confidential information from user connections.

While there are currently no signs of this flaw being exploited in the wild, both the NSA and the DHS Cybersecurity and Infrastructure Security Agency (CISA) issue urgent warnings to install the January 2020 Patch Tuesday updates immediately. Government officials emphasize that rapid adoption of the patch is the only known mitigation and stress that remote exploitation tools will likely become widely available if systems remain unpatched.

Read More at the original source →