VU#849224: Microsoft Windows CryptoAPI fails to properly validate ECC certificate chains

The Microsoft Windows CryptoAPI,which is provided by Crypt32.dll,fails to validate ECC certificates in a way that properly leverages the protections that ECC cryptography should provide. As a result,an attacker may be able to craft a certificate that appears to have the ability to be traced to a trusted root certificate authority. Any software,including third-party non-Microsoft software,that relies on the Windows CertGetCertificateChain()function to determine if an X.509 certificate can be traced to a trusted root CA may incorrectly determine the trustworthiness of a certificate chain.

Support the originator by clicking the read the rest link below.