Security News > 2023 > January > Researchers Release PoC Exploit for Windows CryptoAPI Bug Discovered by NSA

Researchers Release PoC Exploit for Windows CryptoAPI Bug Discovered by NSA
2023-01-26 14:52

Proof-of-concept (Poc) code has been released for a now-patched high-severity security flaw in the Windows CryptoAPI that the U.S. National Security Agency (NSA) and the U.K. National Cyber Security Centre (NCSC) reported to Microsoft last year. Tracked as CVE-2022-34689 (CVSS score: 7.5), the spoofing vulnerability was addressed by the tech giant as part of Patch Tuesday updates released in


News URL

https://thehackernews.com/2023/01/researchers-release-poc-exploit-for.html

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2022-10-11 CVE-2022-34689 Authentication Bypass by Spoofing vulnerability in Microsoft products
Windows CryptoAPI Spoofing Vulnerability
network
low complexity
microsoft CWE-290
7.5

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
NSA 2 0 2 7 5 14