← Back to Pulse Feed
PULSE DETAIL
CVE2020-0601 is a Curveball vulnerability that could allow attackers to spoof signatures and is a high cryptographic validation flaw. Per NIST, "A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates. An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source, aka 'Windows CryptoAPI Spoofing Vulnerability',".
Indicators of Compromise (4 / 1058 total)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-SHA1 | f35273742ccdfbc44e5867347765aa8c0e37b215 | — | 2026-05-13 | |
| FileHash-SHA1 | b4246b529fa6aa05e1d146070c64a8eacbccb9e1 | SHA1 of 00000006e9d3a7e85d1f1e7711787b9a117655e249a565122ee12e9962199007 | 2026-05-13 | |
| FileHash-SHA1 | 6c865cb3a2b51a3ef44235986b25dd541563bace | SHA1 of 22aa981f10e839fbf2c5c3a8f3de7caa2f9c3add7af4750420fd2b1a05be1709 | 2026-05-13 | |
| FileHash-SHA1 | 936b54a457c3c556f9450b145fe8c2c37e39edb2 | SHA1 of dfbde381fde1a284c81a72d06a1a43faf49cd1c085c87234e34e50b881567806 | 2026-05-13 |