Security Research

CVE-2020-0601 CurveBall: ECC Elliptic Curve Spoofing in Windows CryptoAPI

#Vulnerability Analysis#Code Audit#Supply Chain Attack
ECC isomorphic curve bypasses Windows trust chain

CurveBall lets attackers forge a certificate that bypasses the entire Windows trust chain — all it takes is computing a pair of “isomorphic but different” elliptic curve keys, and any certificate they sign will be trusted.

Unlock to view this content.