Researchers published proof-of-concept (PoC) code exploits for a recently-patched CVE-2020-0601 flaw in the Windows operating system reported by the US National Security Agency. The flaw, dubbed NSACrypt or CurveBall, resides in the Crypt32.dll module that contains various Certificate and Cryptographic Messaging functions used by the Windows Crypto API for data encryption. An attacker could exploit the flaw by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted source.”]
Source: https://securityaffairs.co/wordpress/96486/uncategorized/cve-2020-0601-nsacrypto-exploits.html

