A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source, aka 'Windows CryptoAPI Spoofing Vulnerability'.
Published: 2020-01-14
Microsoft kicks off the first Patch Tuesday of 2020 with the disclosure of CVE-2020-0601, a highly critical flaw in the cryptographic library for Windows. UPDATE 01/16/2020: This blog post has been updated to reflect the availability of proof-of-concept code for CVE-2020-0601, which is being referred to as CurveBall or Chain of Fools.
https://www.tenable.com/cyber-exposure/2020-threat-landscape-retrospective
https://media.defense.gov/2020/Jan/14/2002234275/-1/-1/0/CSA-WINDOWS-10-CRYPT-LIB-20190114.PDF
https://github.com/nichxlxs/cve-research
https://github.com/b4nxzz/CVEs
https://github.com/AndreLlorente/NVD_CVE_EXTRACTOR
https://github.com/ShayNehmad/twoplustwo
https://github.com/bsides-rijeka/meetup-2-curveball
https://github.com/eastmountyxz/CSDNBlog-Security-Based
https://github.com/eastmountyxz/CVE-2018-20250-WinRAR
https://github.com/eastmountyxz/CVE-2020-0601-EXP
https://github.com/talbeerysec/CurveBallDetection
https://github.com/gentilkiwi/curveball
https://github.com/dlee35/curveball_lua
https://github.com/thimelp/cve-2020-0601-Perl
https://github.com/Doug-Moody/Windows10_Cumulative_Updates_PowerShell
https://github.com/0xxon/cve-2020-0601-utils
https://github.com/0xxon/cve-2020-0601-plugin
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-0601
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0601
Published: 2020-01-14
Updated: 2026-06-17
Named Vulnerability: CurveBallNamed Vulnerability: ChainOfFoolsNamed Vulnerability: Chain of FoolsNamed Vulnerability: CURVEBALLKnown Exploited Vulnerability (KEV)
Base Score: 5.8
Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:N
Severity: Medium
Base Score: 8.1
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Severity: High
EPSS: 0.89436