#Microsoft’s #patch for #CVE-2020-0601 introduces a call to #CveEventWrite in #CryptoAPI when a faked certificate is detected.
Didier Stevens wrote a script that will write a Windows event entry in the Application event log.
#Test #Alert #blueteam
https://blog.didierstevens.com/2020/01/15/using-cveeventwrite-from-vba-cve-2020-0601/
#microsoft #patch #cve #CveEventWrite #cryptoapi #test #alert #blueteam