<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>CVE-2020-0601 Archives - Kontech IT Services</title>
	<atom:link href="http://kontech.net/tag/cve-2020-0601/feed/" rel="self" type="application/rss+xml" />
	<link>https://kontech.net/tag/cve-2020-0601/</link>
	<description>We get IT done</description>
	<lastBuildDate>Wed, 15 Jan 2020 04:22:35 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>http://kontech.net/wp-content/uploads/cropped-logo-square-32x32.png</url>
	<title>CVE-2020-0601 Archives - Kontech IT Services</title>
	<link>https://kontech.net/tag/cve-2020-0601/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Update All Windows Systems Now! CVE-2020-0601</title>
		<link>http://kontech.net/update-all-windows-systems-now-cve-2020-0601/</link>
					<comments>http://kontech.net/update-all-windows-systems-now-cve-2020-0601/#respond</comments>
		
		<dc:creator><![CDATA[k0k0t]]></dc:creator>
		<pubDate>Wed, 15 Jan 2020 04:21:18 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[4528760]]></category>
		<category><![CDATA[CVE-2020-0601]]></category>
		<category><![CDATA[Microsoft confirms CryptoAPI spoofing vulnerability]]></category>
		<category><![CDATA[NSA confirms Windows 10 flaw]]></category>
		<guid isPermaLink="false">http://kontech.net/?p=3938</guid>

					<description><![CDATA[<p>There appears to be a high-priority patch Tuesday alert today! According to numerous media posts, there is a vulnerability that is present on all versions of Windows from XP and newer. Rumor has it, it is so serious that the U.S. Military apparently received their patches ahead of time under NDAs. The NSA&#8217;s director of <a href="http://kontech.net/update-all-windows-systems-now-cve-2020-0601/" rel="nofollow"><span class="sr-only">Read more about Update All Windows Systems Now! CVE-2020-0601</span>[...]</a></p>
<p>The post <a href="http://kontech.net/update-all-windows-systems-now-cve-2020-0601/">Update All Windows Systems Now! CVE-2020-0601</a> appeared first on <a href="http://kontech.net">Kontech IT Services</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p> There appears to be a high-priority patch Tuesday alert today! According to numerous media <a rel="noreferrer noopener" aria-label="posts (opens in a new tab)" href="https://www.washingtonpost.com/national-security/nsa-found-a-dangerous-microsoft-software-flaw-and-alerted-the-firm--rather-than-weaponize-it/2020/01/14/f024c926-3679-11ea-bb7b-265f4554af6d_story.html" target="_blank">posts</a>, there is a vulnerability that is present on all versions of Windows from XP and newer. Rumor has it, it is so serious that the U.S. Military apparently received their patches ahead of time under NDAs.</p>



<p> The NSA&#8217;s director of cyber security, Anne Neuberger, has&nbsp;confirmed a flaw exists in Windows 10 that &#8220;makes trust vulnerable&#8221;&nbsp;and was reported to Microsoft by the NSA itself. </p>



<p> An investigative reporter Brian Krebs said that&nbsp;<a rel="noreferrer noopener" href="https://krebsonsecurity.com/2020/01/cryptic-rumblings-ahead-of-first-2020-patch-tuesday/" target="_blank">his sources told him</a>, &#8220;Microsoft is slated to release a software update on Tuesday to fix an extraordinarily serious security vulnerability in a core cryptographic component present in all versions of Windows.&#8221; </p>



<p>Moving past the speculations,  Microsoft has officially <a rel="noreferrer noopener" href="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0601" target="_blank">confirmed the vulnerability</a>. It stated that &#8220;A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.&#8221; This means that an attacker could be able to exploit this, in a way that the NSA said &#8220;makes trust vulnerable,&#8221; by using a spoofed code-signing certificate. By so doing, a malicious file could appear to come from a legitimate and trusted source. </p>



<p>&#8220;A successful exploit could also allow the attacker to conduct man-in-the-middle attacks and decrypt confidential information on user connections to the affected software,&#8221; Microsoft said, adding that &#8220;the security update addresses the vulnerability by ensuring that Windows CryptoAPI completely validates ECC certificates.&#8221; </p>



<p>What to do then?</p>



<p>All Windows 10 users are advised to apply the Patch Tuesday update as soon as it becomes available to them.  However, as of this writing &nbsp;the <a rel="noreferrer noopener" aria-label="emergency update (opens in a new tab)" href="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0601" target="_blank">emergency update</a> only applies to Windows 10, Server 2016, and Server 2019. </p>
<p>The post <a href="http://kontech.net/update-all-windows-systems-now-cve-2020-0601/">Update All Windows Systems Now! CVE-2020-0601</a> appeared first on <a href="http://kontech.net">Kontech IT Services</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>http://kontech.net/update-all-windows-systems-now-cve-2020-0601/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">3938</post-id>	</item>
	</channel>
</rss>
