Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

The NSA disclosed CVE-2020-0601 on January 14, 2020: a flaw in Windows CryptoAPI that could make certain forged elliptic-curve certificates appear trustworthy. Microsoft released a fix that day. The vulnerability is now a historical, patched issue; for Windows 10 users in 2026, the bigger question is whether the computer still receives security updates. Ordinary Windows 10 support ended October 14, 2025, though eligible users can use Extended Security Updates and some LTSC editions have separate lifecycles.

What the NSA found

The vulnerability, tracked as CVE-2020-0601 and often called “CurveBall,” affected Windows CryptoAPI, including the user-mode cryptographic library CRYPT32.DLL. The flaw was in how Windows validated certificates using elliptic-curve cryptography. A carefully crafted certificate could be treated as if it had been issued by a trusted authority, even when it had not.

Certificates help a computer establish the identity of a website, software publisher, or other endpoint. Windows uses certificate checks in a range of trust decisions, including HTTPS connections, signed software, and secure network workflows. If a vulnerable system accepted a counterfeit certificate, an attacker could make a malicious site, program, or network endpoint appear legitimate.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

That is a trust-spoofing problem, not a universal break of encryption. CVE-2020-0601 did not automatically let an attacker read every encrypted connection, remotely compromise every Windows 10 computer, or execute code merely by existing. A successful attack depended on an opportunity to exploit a vulnerable system and on the relevant application or trust path relying on the affected Windows validation behavior. Practical impact could therefore vary by application.

Microsoft’s January 2020 advisory characterized the vulnerability as Important. The NSA warned that it could undermine trust in network connections and help malicious code appear to come from a legitimate source. Those descriptions point to a high-impact weakness in a foundational security mechanism, not a claim that all Windows encryption had been defeated.

Which systems were affected—and when

Microsoft identified affected Windows 10 client releases and Windows Server 2016 and 2019. This was not a flaw in every version of Windows or every Microsoft device. Affected release branches received different cumulative updates, so there was no single January 2020 KB number that applied to every system.

Microsoft shipped the fix on January 14, 2020, correcting the certificate-validation behavior. For example, Microsoft documented KB4534273 for Windows 10 version 1809 and Windows Server 2019; other branches had their own updates. Installing that update—or a later cumulative update that includes it—addresses this specific vulnerability.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

At the time of disclosure, both Microsoft and the NSA said they had not observed active exploitation. That was a January 2020 assessment, not proof that the vulnerability was never exploited later. It also did not remove the need to patch promptly.

Rank #3
HP 2020 15.6" Touchscreen Laptop Computer/ 10th Gen Intel Quard-Core i5 1035G1 up to 3.6GHz/ 12GB DDR4 RAM/ 256GB PCIe SSD/ 802.11ac WiFi/Bluetooth 4.2/ USB 3.1 Type-C/HDMI/Silver/Windows 10 Home
  • 10th Generation Intel Core i5-1035G1 processor
  • 12GB system memory for full-power multitasking
  • 256GB Solid State Drive
  • 15.6" Micro-edge touchscreen display

Why the NSA’s public disclosure stood out

The NSA publicly accepted credit for discovering CVE-2020-0601, an unusual move that CyberScoop reported as the agency’s first public acknowledgment of discovering a Microsoft vulnerability. The agency said disclosure was intended in part to build trust in its vulnerability-disclosure practices. The episode also illustrated the U.S. government’s Vulnerabilities Equities Process, through which officials weigh whether to retain vulnerability information for intelligence use or share it so a vendor can fix the issue.

Publicly attributing this discovery does not establish that the NSA always chooses disclosure, nor does it show that the flaw was used by an adversary. Microsoft produced and distributed the fix; the NSA’s role was discovery and disclosure.

Rank #4
Dell Latitude 7480 Laptop 14 - Intel Core i7 6th Gen - i7-6600U - 3.4Ghz - 256GB SSD - 16GB RAM - 1920x1080 FHD - Windows 10 Pro (Renewed)
  • Latitude 7480 Laptop 14"
  • Intel Core i7 6th Gen i7-6600U -Core Processor 2.6GHz (3.4GHz With Turbo Boost)
  • 256 GB SSD Hard Drive & 16GB Memory
  • 1920x1080 FHD resolution Non-Touch with Webcam and an integrated graphics chip
  • Wireless Wifi & Bluetooth

What CISA required in 2020

CISA issued Emergency Directive 20-02, requiring covered U.S. federal civilian agencies to mitigate the Windows vulnerabilities in the directive by 5 p.m. EST on January 29, 2020. Agencies were told to prioritize, among other systems, mission-critical assets, internet-accessible systems, and servers, and to ensure newly provisioned or disconnected machines were patched before reconnecting.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

That deadline was mandatory for agencies within the directive’s scope. It was not a legal order to ordinary consumers or every private company, although the urgency and prioritization guidance were useful beyond government.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What Windows 10 users should do now

If a computer has received normal Windows cumulative updates since January 2020, it will generally have the fix for CVE-2020-0601. To check for available updates on a Windows 10 machine, open Settings → Update & Security → Windows Update and select Check for updates. Install available updates and restart if prompted. In a managed workplace, updates may instead be delivered through tools such as Windows Server Update Services, Configuration Manager, or Intune.

That check is not enough to establish the computer’s overall security status in 2026. Microsoft ended ordinary support for Windows 10 on October 14, 2025. For Home and Pro, version 22H2 was the final release. A system can be patched for this six-year-old flaw yet miss security fixes for vulnerabilities found after support ended.

  • If the device supports Windows 11: Plan to upgrade and keep the new system current. Microsoft’s Windows 11 page provides the official upgrade information.
  • If you need more time: Eligible consumers can use Microsoft’s Windows 10 Extended Security Updates program as a temporary bridge, with protection stated through October 12, 2027. ESU does not restore ordinary Windows 10 support or replace a migration plan.
  • If the device cannot move to Windows 11: Consider replacing it or using another supported platform, particularly if it handles sensitive information or connects to the internet.
  • If it runs LTSC or Windows Server: Check the lifecycle for the exact edition and release. LTSC and server products can have support dates different from ordinary Windows 10 Home and Pro.

Microsoft’s current Windows 10 support guidance explains the end of support and ESU options. A browser update or antivirus product is not a substitute for an operating-system security update; neither was the remedy for CVE-2020-0601.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Checklist for IT teams

  • Inventory Windows 10 endpoints and Windows Server 2016/2019 systems, including machines that are offline, dormant, newly provisioned, or rarely connected.
  • Use centralized patch-compliance reporting to confirm the January 2020 fix, or a later cumulative update containing it, is installed. Do not rely on a device’s Windows version alone to prove patch status.
  • Prioritize internet-facing systems, servers, privileged-user endpoints, high-value assets, and mission-critical services when addressing unpatched machines.
  • Review certificate and code-signing anomalies where an endpoint remained exposed and unpatched during the relevant period; investigate based on telemetry and risk rather than assuming compromise.
  • Document a migration or support plan for systems on unsupported Windows releases. For a managed fleet, endpoint-management and detection tools can help track compliance, but they do not replace OS updates.

Timeline

Date What happened
January 14, 2020 The NSA publicly disclosed CVE-2020-0601; Microsoft released the security updates; CISA issued Emergency Directive 20-02.
January 29, 2020 Deadline for covered federal civilian agencies to meet the directive’s patching requirements.
October 14, 2025 Ordinary Windows 10 support ended for the standard Home and Pro lifecycle.
August 2026 CVE-2020-0601 is a historical patched issue; remaining Windows 10 users need a supported release, applicable ESU coverage, or an edition-specific support plan.

What the headline does—and does not—mean

The NSA found a consequential flaw in a Windows certificate-validation mechanism, and Microsoft patched it on the day it was disclosed. It did not mean every Windows 10 computer had been hacked, all secure traffic could be decrypted, or the flaw was known to be actively exploited in January 2020. Today, confirming that old fix is worthwhile, but keeping the operating system within a supported security-update lifecycle matters more.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.