VDB

GCVE-110-CERTCC-2020-849224

GCVE-110-CERTCC-2020-849224
Advisory PublishedCVSS 9.4/10
Vulnetix · Advisory published January 14, 2020
The Microsoft Windows CryptoAPI fails to properly validate certificates that use Elliptic Curve Cryptography (ECC), which may allow an attacker to spoof the validity of certificate chains.

Risk Scores

CVSS 2.0
9.4/10
Critical · AV:N/AC:L/Au:N/C:C/I:C/A:N
certcc-cam
certcc-cam
impact0population0exploitation1widely_known0score_current0ease_of_exploitation0
certcc-vrda
certcc-vrda
d1_direct_report1
certcc-cvss-temporal-env
certcc-cvss-temporal-env
temporal_score9.4remediation_levelUreport_confidenceCenvironmental_score9.4346745024target_distributionNDenvironmental_vectorCDP:ND/TD:ND/CR:ND/IR:ND/AR:ND

Browse GCVE Records

74,352 records in the GCVE database · Updated July 22, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›