Vulnerability in Windows Hello allows hackers to bypass biometric security on business PCs

A vulnerability has been identified in the Windows Hello for Business (WHfB) authentication system that allows attackers to bypass the biometric protection of computers and laptops. WHfB was susceptible to attacks using a method of reducing the level of security, despite the use of cryptographic keys, reports the Dark Reading portal.

Image source: Microsoft

WHfB is a feature available in commercial and enterprise editions of Windows 10 since 2016. It uses cryptographic keys stored in the computer’s Trusted Platform Module (TPM) and is activated using biometric or PIN authentication. The feature was supposed to provide a higher level of security compared to passwords or one-time passwords (OTP) sent via SMS.

The vulnerability allows hackers to lower the level of authentication security, allowing access to user accounts. An attacker can intercept and modify POST requests to the Microsoft authentication service, downgrading the WHfB security level to less secure verification levels such as passwords or OTP.

Microsoft created a patch to address the vulnerability in March, adding a new conditional access feature called Authentication strength that administrators can now enable in the Azure Portal. The new update allows you to force only phishing-resistant authentication methods to be used, leaving no room for security compromises.

Experts emphasize that the WHfB system itself remains secure, but organizations need to properly configure conditional access policies to prevent the possibility of downgrading authentication security.

admin

Share
Published by
admin

Recent Posts

Chinese hypersonic drone with detonation engine will take off in 2026 – a year earlier than planned

The Chinese company Sichuan Lingkong Tianxing Technology presented a model of the hypersonic drone Cuantianhou…

50 minutes ago

Blu-ray, goodbye! Sony announced the closure of its last optical disc plant

Sony announced it would cease production of Blu-ray Disc (BD) optical storage media in February.…

1 hour ago

Autumn Moscow, interesting quests and graphics better than in S.T.A.L.K.E.R. 2: data miners have revealed new details of the next Metro

The “Around-Builds Metro 2033|Last Light|Exodus” community, which studies the history and various builds of games…

1 hour ago

Apple will answer in court for toxic and hazardous chemicals in smartwatch straps

A lawsuit has been filed in the Northern District Court of California against Apple, which,…

2 hours ago

ChatGPT stopped opening all over the world – thousands of users had to think for themselves

Today, users from different countries began to massively report the unavailability of the world's most…

2 hours ago

A hole was found in Subaru’s software that made it possible to remotely unlock, start and monitor millions of cars.

Cybersecurity researchers Sam Curry and Shubham Shah discovered vulnerabilities in Subaru's Starlink infotainment system (not…

2 hours ago