Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Researchers published proof-of-concept code for CVE-2020-0601, a Windows CryptoAPI certificate-validation flaw Microsoft patched on January 14, 2020. The demonstrations showed how crafted elliptic-curve certificates could spoof code-signing and TLS trust scenarios. They established a technical attack path—not that the flaw was being exploited in the wild.

What was CVE-2020-0601?

CVE-2020-0601, known as CurveBall and Chain of Fools, was a spoofing vulnerability in Windows CryptoAPI’s handling of elliptic-curve cryptography certificates. CryptoAPI includes certificate and cryptographic messaging functions in crypt32.dll; Windows relies on certificate validation when deciding whether to trust signed content or a connection. The CVE Program identifies the issue as a vulnerability in that validation process: CVE-2020-0601 record.

The security consequence was not that every signed file or encrypted connection became unsafe. Rather, a successful spoof could undermine a trust decision by making a certificate appear to represent a trusted signer or endpoint when it did not.

What did the proof of concept demonstrate?

The ly4k/ollypwn repository describes the defect as a failure to check the elliptic-curve generator parameter, G. In its account, a certificate could supply its own generator while the Windows validation path compared public keys against a trusted certificate authority. The repository includes demonstrations for two distinct scenarios: CurveBall proof-of-concept repository.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall

Code-signing certificate spoofing

A crafted certificate could be used in a code-signing scenario to make a malicious executable appear to come from a trusted, legitimate source. Microsoft’s warning, as quoted by BleepingComputer, described an attacker using a spoofed code-signing certificate to sign a malicious executable so it appeared to be from a trusted source.

TLS certificate spoofing

The repository also demonstrates a TLS certificate scenario. If a system accepted a forged certificate as trusted, an attacker in a position to intercept a connection could potentially impersonate an endpoint. This is a separate demonstration from code signing; neither should be read as proof that attacks were occurring broadly or that any arbitrary remote attacker could compromise a Windows machine.

Rank #2
Dell Latitude 5420 14" FHD Business Laptop Computer, Intel Quad-Core i5-1145G7, 16GB DDR4 RAM, 256GB SSD, Camera, HDMI, Windows 11 Pro (Renewed)
  • 256 GB SSD of storage.
  • Multitasking is easy with 16GB of RAM
  • Equipped with a blazing fast Core i5 2.00 GHz processor.

Why did the flaw matter, and what did it not mean?

Certificate checks underpin trust in signed executables, HTTPS connections, email, and other signed files. Tenable’s analysis described the potential for attackers to abuse that trust, while noting that they would still need a way to deliver malicious content or get into the relevant communication path—for example, through phishing or a man-in-the-middle position: Tenable’s CVE-2020-0601 analysis.

Contemporaneous reporting discussed possible interception or modification of TLS communications and potential remote code execution. These were potential consequences of exploiting the flaw, not reports that the proof-of-concept code had caused those outcomes in real-world attacks. The distinction matters: a proof of concept shows how a vulnerability may be exercised; it does not by itself establish exploitation, successful compromise, or prevalence.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
HP OmniBook 3 17.3 inch Laptop PC, FHD Display, AMD Ryzen 3 30, 8 GB RAM, 512 GB SSD, AMD Radeon 610M Graphics, Windows 11 Home, Mica Silver, 17-dp0199nr
  • FULL HD IPS DISPLAY - Enjoy vibrant, crystal-clear images with 178-degree wide-viewing angles
  • AMD RYZEN 3 30 PROCESSOR - Everyday performance you can count on; Multitask, stream, game casually, and edit photos smoothly with responsive power and vibrant HDR visuals
  • ENJOY UP TO 14 HOURS AND 15 MINUTES OF BATTERY LIFE - HP Fast Charge restores battery from 0 to 50% in approximately 45 minutes
  • AMD RADEON 610M GRAPHICS - Experience smooth entertainment; Built for streaming and multitasking, enjoy realistic visuals and efficient performance for work and play
  • STORAGE AND MEMORY - 512 GB PCIe NVMe M.2 SSD offers fast speed and efficient storage; and 8 GB LPDDR5 RAM memory boosts performance with higher bandwidth

Was CurveBall being exploited in the wild?

In the immediate January 2020 coverage, Microsoft and the NSA had not seen exploitation in the wild. That statement describes what was known at the time, not the current status of every system or a guarantee about later events. Public proof-of-concept code appeared shortly after Microsoft’s update, making the issue easier to study and potentially operationalize, but publication alone was not evidence of active attacks.

Which Windows versions were affected?

Disclosure-era reporting identified Windows 10 and Windows Server 2016 and 2019 as affected. That historical list should not be extrapolated to every Windows release, nor does it establish whether a particular computer is protected today. Microsoft’s version-specific security guidance is the appropriate reference for a particular Windows release and update state: Microsoft Security Response Center: CVE-2020-0601.

Rank #4
HP 14" HD Laptop, Windows 11, Intel Celeron Dual-Core Processor Up to 2.60GHz, 4GB RAM, 64GB SSD, Webcam, Dale Blue (Renewed)
  • 14” Diagonal HD BrightView WLED-Backlit (1366 x 768), Intel Graphics,
  • Intel Celeron Dual-Core Processor Up to 2.60GHz, 4GB RAM, 64GB SSD
  • 3x USB Type A,1x SD Card Reader, 1x Headphone/Microphone
  • 802.11a/b/g/n/ac (2x2) Wi-Fi and Bluetooth, HP Webcam with Integrated Digital Microphone
  • Windows 11 OS, Dale Blue
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What was the timeline?

  • January 14, 2020: Microsoft released its January security updates, including the fix. Tenable reports that the NSA disclosed the vulnerability to Microsoft through coordinated vulnerability disclosure.
  • January 15, 2020: Tenable records Danish researcher ollypwn publishing a CurveBall proof of concept on GitHub, alongside work by other researchers.
  • January 16, 2020: BleepingComputer reported publicly released proof-of-concept code from ollypwn and Kudelski Security: BleepingComputer’s January 16, 2020 report.

How was the vulnerability addressed?

Microsoft’s fix was a security update. The NSA’s contemporaneous advice, quoted in BleepingComputer’s January 16, 2020 report, was: “Rapid adoption of the patch is the only known mitigation at this time and should be the primary focus for all network owners.” This was guidance in 2020; it is not a substitute for checking whether a specific device has the applicable update installed.

  1. Identify the Windows edition and release on the systems you manage.
  2. Use Microsoft’s CVE-2020-0601 security guidance to determine the relevant update and applicability for that release.
  3. Install the applicable security update through your organization’s established Windows update process, then verify update compliance in your management or vulnerability-scanning tools.

CISA directed U.S. agencies in 2020 to patch affected endpoints within 10 business days. That was a historical remediation deadline, not a measure of infections or exploitation. A vulnerability scan configured to detect CVE-2020-0601 can help administrators find systems requiring attention, but scanning does not replace installing Microsoft’s update.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Quick Recap

SaleBestseller No. 1
HP 14' HD Laptop, Windows 11, Intel Celeron Dual-Core Processor Up to 2.60GHz, 4GB RAM, 64GB SSD, Webcam, Dale Pink (Renewed)
HP 14" HD Laptop, Windows 11, Intel Celeron Dual-Core Processor Up to 2.60GHz, 4GB RAM, 64GB SSD, Webcam, Dale Pink (Renewed)
14" diagonal, 1366x768 resolution, HD BrightView LED, Glossy NON-TOUCH Display
$209.99
Bestseller No. 2
Dell Latitude 5420 14' FHD Business Laptop Computer, Intel Quad-Core i5-1145G7, 16GB DDR4 RAM, 256GB SSD, Camera, HDMI, Windows 11 Pro (Renewed)
Dell Latitude 5420 14" FHD Business Laptop Computer, Intel Quad-Core i5-1145G7, 16GB DDR4 RAM, 256GB SSD, Camera, HDMI, Windows 11 Pro (Renewed)
256 GB SSD of storage.; Multitasking is easy with 16GB of RAM; Equipped with a blazing fast Core i5 2.00 GHz processor.
$304.00
Bestseller No. 4
HP 14' HD Laptop, Windows 11, Intel Celeron Dual-Core Processor Up to 2.60GHz, 4GB RAM, 64GB SSD, Webcam, Dale Blue (Renewed)
HP 14" HD Laptop, Windows 11, Intel Celeron Dual-Core Processor Up to 2.60GHz, 4GB RAM, 64GB SSD, Webcam, Dale Blue (Renewed)
14” Diagonal HD BrightView WLED-Backlit (1366 x 768), Intel Graphics,; Intel Celeron Dual-Core Processor Up to 2.60GHz, 4GB RAM, 64GB SSD
$247.99

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.