SB2020041444 - Security Feature Bypass in Microsoft MSR JavaScript Cryptography Library
Published: April 14, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Security Features (CVE-ID: CVE-2020-1026)
This vulnerability allows a local user to bypass security rescritions feature.
The vulnerability exists in the MSR JavaScript Cryptography Library due to multiple bugs in the library’s Elliptic Curve Cryptography (ECC) implementation. A remote attacker can gain information about a server’s private ECC key (a key leakage attack) or craft an invalid ECDSA signature that nevertheless passes as valid.
Remediation
Install update from vendor's website.