利用 Windows CryptoAPI 漏洞
blog.trailofbits.com | 漏洞 | #windows | #cryptography | #trail-of-bits | #code-signing | #cryptoapi | #spoofing | #ecc | #certificate-validation | #cve-2020-0601 | #certificate-forgery
摘要
NSA 披露 Windows 10 与 Server 2016/2019 的 CryptoAPI 证书校验漏洞后,Trail of Bits 深入剖析 Crypt32.dll 未正确验证椭圆曲线参数的问题:攻击者可借此伪造 HTTPS 与代码签名证书。文中包含玩具版攻击演示与修复建议。
- 发布时间
- 收录时间
Skip to content