Certificate validation bypass on Windows in crypto/x509
A Windows vulnerability allows attackers to spoof valid certificate chains when the system root store is in use.
A workaround is present in Go 1.12.6+ and Go 1.13.7+, but affected users should additionally install the Windows security update to protect their system.
See https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2020-0601 for details on the Windows vulnerability.
为什么是这个 VPI(可解释·实验性)
VPI 计算依据
| 影响度(默认值(无数据)) | 55.00 |
| 利用信号(KEV 收录) | ×1.50 |
| VPI | 82.50 |
VPI 公式 vpi-v1
必要措施
Apply updates per vendor instructions.