>

CurveBall CVE-2020-0601: Forging Trust With One Elliptic Curve Parameter

On 14 January 2020, Microsoft's first Patch Tuesday of the decade included a fix for CVE-2020-0601, a cryptographic implementation flaw in Windows CryptoAPI reported to the vendor by the U.S. National Security Agency. The bug let anyone forge TLS certificates that appeared to chain to the U.S. government's ECC trusted root, making malicious HTTPS sites look legitimately signed. Researchers named it CurveBall, proof-of-concept exploits appeared within days, and CISA issued Emergency Directive 20-02 ordering federal agencies to hunt and patch. This is the story of how a single mishandled curve parameter undermined certificate trust Windows-wide.

Continue ReadingCurveBall CVE-2020-0601: Forging Trust With One Elliptic Curve Parameter
>