Vulnerability in Windows Hello allows hackers to bypass biometric security on business PCs

A vulnerability has been identified in the Windows Hello for Business (WHfB) authentication system that allows attackers to bypass the biometric protection of computers and laptops. WHfB was susceptible to attacks using a method of reducing the level of security, despite the use of cryptographic keys, reports the Dark Reading portal.

Image source: Microsoft

WHfB is a feature available in commercial and enterprise editions of Windows 10 since 2016. It uses cryptographic keys stored in the computer’s Trusted Platform Module (TPM) and is activated using biometric or PIN authentication. The feature was supposed to provide a higher level of security compared to passwords or one-time passwords (OTP) sent via SMS.

The vulnerability allows hackers to lower the level of authentication security, allowing access to user accounts. An attacker can intercept and modify POST requests to the Microsoft authentication service, downgrading the WHfB security level to less secure verification levels such as passwords or OTP.

Microsoft created a patch to address the vulnerability in March, adding a new conditional access feature called Authentication strength that administrators can now enable in the Azure Portal. The new update allows you to force only phishing-resistant authentication methods to be used, leaving no room for security compromises.

Experts emphasize that the WHfB system itself remains secure, but organizations need to properly configure conditional access policies to prevent the possibility of downgrading authentication security.

admin

Share
Published by
admin

Recent Posts

Despelote — goo-o-o-o-o-o-o-o-o-o-ol! Review

One of my first memories (or perhaps the very first one – is it possible…

5 hours ago

Design and specifications of the flagship smartphone Sony Xperia 1 VII leaked online

A few days before the official presentation, details about the new flagship Sony Xperia 1…

5 hours ago

GTA VI Delay to 2026 Causes New Panic Among Game Developers

Bloomberg journalist Jason Schreier reported on the domino effect triggered by the recent delay of…

6 hours ago

Nintendo warns it will block consoles for users who engage in piracy and hacking

Nintendo has updated its user agreement, formalizing the right to remotely disable Switch consoles if…

7 hours ago

Gigabyte Unveils X870 and B850 Aorus Stealth Motherboards with Back-Side Power Connectors

Gigabyte has unveiled the X870 Aorus Stealth and B850 Aorus Stealth motherboards for Ryzen 7000,…

8 hours ago

Alienware Unveils Thin, Affordable Aurora 16 and 16X Gaming Laptops with Understated Designs

Alienware, a subsidiary of Dell known for its futuristic gaming laptops, has released new high-performance…

1 day ago