Security researchers publish first proof-of-concept (PoC) for the Windows vulnerability recently revealed by the US National Security Agency (NSA).
The bug, which some call CurveBall, affects CryptoAPI (Crypt32.dll), a component that handles cryptographic functions on the Windows operating system.
According to a high-level technical analysis of the bug by researcher Tal Be'ery, "the cause of this vulnerability is the incorrect implementation of Elliptic Curve Cryptography (ECC) within Microsoft's code."
According to the NSA, DHS and Microsoft, the error (has been registered as CVE-2020-0601) may allow an attacker to:
start attacks MitM (Man-in-the-middle) and fake HTTPS connections
to sign files and emails with fake signatures
to sign digitally executable code running within Windows
The principles of USA αντέδρασαν άμεσα και προληπτικά στην συγκεκριμένη ευπάθεια. Η NSA δημοσίευσε μια warning ασφαλείας (κάτι πολύ σπάνιο) για το σφάλμα και το τμήμα CISA της DHS εξέδωσε μια οδηγία έκτακτης ανάγκης, δίνοντας στις κυβερνητικές υπηρεσίες δέκα ημέρες για να ενημερώσουν τα συστήματά τους.
This is the first time the NSA has reported a bug to Microsoft. It could be said that the service is releasing press releases to improve its image in the cyber security community after the EternalBlue debacle that was stolen and released by the Shadow Brokers. The specific hacking tools developed by the NSA and leaked online, were used in some of the largest malware infections and cyber attacks to date.
Security experts such as Thomas Ptacek and Kenneth White have confirmed the severity and broad impact of the vulnerability, although it does not affect the Windows Update mechanism, which would make the threat a nightmare.
In a blog post Tuesday, Kenneth White said he knew some people needed a few more days to create a PoC that exploits the CurveBall vulnerability.
The first to mention it was Saleem Rashid, who created a proof-of-concept to show how he can make fake TLS certificates and serve them legally.
Rashid did not publish his code, but others did so a few hours later. CurveBall's first public PoC was released by Kudelski Security, while o second was a Danish security researcher under the pseudonym Ollypwn.
The good news among all this is that even if you haven't updated your system with the latest patch Tuesday, Windows Defender has received the necessary updates to detect any attempts to actively exploit the bug and warn users.