VDB
GCVE-110-CERTCC-2020-849224
GCVE-110-CERTCC-2020-849224
Advisory PublishedCVSS 9.4/10
The Microsoft Windows CryptoAPI fails to properly validate certificates that use Elliptic Curve Cryptography (ECC), which may allow an attacker to spoof the validity of certificate chains.
Risk Scores
CVSS 2.0
9.4/10
Critical · AV:N/AC:L/Au:N/C:C/I:C/A:N
certcc-cam
certcc-cam
impact0population0exploitation1widely_known0score_current0ease_of_exploitation0
certcc-vrda
certcc-vrda
d1_direct_report1
certcc-cvss-temporal-env
certcc-cvss-temporal-env
temporal_score9.4remediation_levelUreport_confidenceCenvironmental_score9.4346745024target_distributionNDenvironmental_vectorCDP:ND/TD:ND/CR:ND/IR:ND/AR:ND
Aliases
References
Browse GCVE Records
74,352 records in the GCVE database · Updated July 22, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.