CurveBall Windows Spoofing Vulnerability
Microsoft has released details of a cryptographic vulnerability in Windows 10 and Windows Server 2016 or 2019 that allows a threat actor to impersonate trusted providers.
Summary
Microsoft has released details of a cryptographic vulnerability in Windows 10 and Windows Server 2016 or 2019 that allows a threat actor to impersonate trusted providers.
Affected platforms
The following platforms are known to be affected:
- Microsoft Windows 10
- Microsoft Windows Server 2016 & 2019
Threat details
The vulnerability is caused by incorrect validation of Elliptic Curve Cryptography (ECC) certificates. An attacker can exploit this flaw to sign a trojan or other malware executable, with users being told by Windows that it is from a legitimate source. A threat actor with network infrastructure access could also conduct a Man-in-the-Middle (MitM) attack to redirect HTTPS connections to a spoof website.
Multiple proof-of-concept exploits have been released that demonstrate how this vulnerability can be misused. At the time of publication, there are no known attacks that have exploited this vulnerability.
For further information:
Remediation steps
| Type | Step |
|---|---|
|
Users and administrators are encouraged to review the following Microsoft update advisories and apply the necessary updates as soon as possible: Additionally, to prevent and detect an infection, ensure that:
|
CVE Vulnerabilities
Last edited: 29 June 2021 12:00 pm