Microsoft's CVE 2020-0601 description says it has to do with ECC certificate spoofing (as do many other articles, some specifically stating that RSA is not affected). Since XP (even with POSReady patches) has never supported any ECC on the OS level (crypt32.dll), how exactly would it be spoofed on XP? I'm not sure how SSL Labs is testing this, but something seems amiss here. Assuming the test works correctly, my logic says it'd have to be a browser problem.