Red Security

Full Version: Urgent !! Windows User Urged to Patch A Critical Crypto Vulnerability on Windows 10
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
In The Name Of Allah
Al-Salam Alekum

[Image: Windows-vulnerability-patch-update.jpg]

Hello guys, today windows 10 users forced to do a urgent update. Tho, Windows 10 as it is the most used system worldwide it never stops updating. Always their are more focus on top systems to explore holes.

Quote:Microsoft released a patch for this critical cryptographic vulnerability and said that the vulnerability in theĀ usermode cryptographic library, CRYPT32.DLL, that affects Windows 10 systems.
Quote:The vulnerability discovered by the National Security Agency (NSA) and confirmed that this critical bug allows an attacker to perform remote code execution on vulnerable Windows client and server.

This critical bug exploited by an attacker to undermine how Windows verifies cryptographic trust and Validate Elliptic Curve Cryptography (ECC) certificates that enable the RCE to take control of the system.




The Source

Stay Safe and Secure :_)
Wa Salam Alekum
This is not so critical.
The RCE which is mentioned is also not as bad as it seems, all that CVE-2020-0601 does is spoofs a sign certificate on executable so it looks like it's signed by a legit company, you still have to double-click the exe or what ever other format that executables come in.
It's the same if I have created a RAT without this exploit, a user would still need to execute it by hand.