Discord Server Red Security Twitter Donation to Red Security Red Security Youtube Channel Red Security Tumblr Profile
Windscribe
Login or Register to Hide ads and Accessing all features on the forum
Thread Rating:
  • 1 Vote(s) - 5 Average
  • 1
  • 2
  • 3
  • 4
  • 5
News Urgent !! Windows User Urged to Patch A Critical Crypto Vulnerability on Windows 10
#1
In The Name Of Allah
Al-Salam Alekum

[Image: Windows-vulnerability-patch-update.jpg]

Hello guys, today windows 10 users forced to do a urgent update. Tho, Windows 10 as it is the most used system worldwide it never stops updating. Always their are more focus on top systems to explore holes.

Quote:Microsoft released a patch for this critical cryptographic vulnerability and said that the vulnerability in the usermode cryptographic library, CRYPT32.DLL, that affects Windows 10 systems.
Quote:The vulnerability discovered by the National Security Agency (NSA) and confirmed that this critical bug allows an attacker to perform remote code execution on vulnerable Windows client and server.

This critical bug exploited by an attacker to undermine how Windows verifies cryptographic trust and Validate Elliptic Curve Cryptography (ECC) certificates that enable the RCE to take control of the system.




The Source

Stay Safe and Secure :_)
Wa Salam Alekum
Rs
* Thankful to Allah *
Kurdy
Reply
#2
This is not so critical.
The RCE which is mentioned is also not as bad as it seems, all that CVE-2020-0601 does is spoofs a sign certificate on executable so it looks like it's signed by a legit company, you still have to double-click the exe or what ever other format that executables come in.
It's the same if I have created a RAT without this exploit, a user would still need to execute it by hand.
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
Question News Windows Running MS-SQL Servers Under Attack!! Hackers Installing 10 Secret Backdoors Mr.Kurd 0 27 7 hours ago
Last Post: Mr.Kurd
Sad News Critical RCE Bug in WordPress Plugin Let Hackers Gain Admin Access on 200,000 Website Mr.Kurd 0 48 Yesterday, 11:19 AM
Last Post: Mr.Kurd
Rainbow News Vulnerability In WPvivid Backup Plugin Could Expose Files Of WordPress Sites Mr.Kurd 0 51 Yesterday, 11:11 AM
Last Post: Mr.Kurd
Rainbow News Microsoft Alerts Users Of Zero-Day RCE Vulnerability In Windows 7 Under Active Exploi Mr.Kurd 0 135 03-26-2020, 09:03 AM
Last Post: Mr.Kurd
Question News Critical Remote Code Execution Bug in Linux Based OpenWrt OS Affects Millions of Netw Mr.Kurd 0 113 03-25-2020, 08:11 AM
Last Post: Mr.Kurd
Exclamation News Hackers Exploiting 2 Unpatched Windows 0-Day Vulnerabilities in Wide – Microsoft Warn Mr.Kurd 0 249 03-24-2020, 07:56 AM
Last Post: Mr.Kurd
Thumbs Down News Slack Vulnerability Allowing Account Takeovers Mr.Kurd 0 84 03-17-2020, 08:11 PM
Last Post: Mr.Kurd
Shocked News Unpatched Wormable Windows SMBv3 RCE Zero-day Flaw Leaked in Microsoft Security Updat Mr.Kurd 0 196 03-12-2020, 09:39 AM
Last Post: Mr.Kurd
Exclamation News A vulnerability that Allows Hackers to Hijack Facebook Accounts Mr.Kurd 0 112 03-04-2020, 07:17 AM
Last Post: Mr.Kurd
Brick News OpenSMTPD Email Server Vulnerability Threatens Many Linux and BSD Systems Mr.Kurd 0 92 03-02-2020, 08:40 PM
Last Post: Mr.Kurd



Users browsing this thread: 1 Guest(s)