< Back to situations

This situation has concluded

It was preserved as a record on September 10; the timeline below shows how it unfolded, with sources. Get the briefing to follow the top situations still developing: three emails a week, sourced and in order.

[SITUATION] · [QUIET] · [TECHNOLOGY]

2 clusters · 2 sources · 16 days · First seen · Last updated

Windows Hello for Business security vulnerabilities

Overview

Security concerns regarding Windows Hello for Business have emerged through technical reports and researcher demonstrations. Initially, the German Federal Office for Information Security (BSI) identified vulnerabilities where attackers with local administrator rights could decrypt and manipulate biometric templates, such as facial or fingerprint data, to impersonate users. The BSI recommended mitigation strategies including the use of Enhanced Sign-in Security (ESS) mode and Trusted Platform Modules (TPM).

Subsequent research expanded on these risks, demonstrating that malware can hijack authentication keys within an active user session to gain persistent access to Microsoft Entra ID environments. This method allows malicious software to exploit native Windows cryptographic interfaces to sign authentication data without needing a PIN or biometric verification. By bypassing TPM hardware protections through the use of an active session, attackers can obtain a Primary Refresh Token (PRT), enabling them to register new devices and maintain long-term, stealthy access to corporate cloud services.

Entities

Windows Hello for Business · Microsoft Entra ID · Microsoft · Dirk-jan Mollema

Timeline

  1. about 1 month ago

    [TECHNOLOGY] 2 sources
    Windows Hello for Business keys vulnerable to malware hijacking

    Malware can bypass PINs and biometrics by hijacking Windows Hello for Business keys to gain persistent, silent access to Microsoft Entra ID cloud environments.

  2. about 2 months ago

    [TECHNOLOGY] 6 sources
    German BSI warns Windows Hello for Business vulnerable to admin‑level attacks

    BSI's new report flags Windows Hello for Business as vulnerable to local admin attacks that can manipulate biometric data, urging ESS, TPM and stricter configuration to protect enterprise logins.

Sources

nouvelles-du-monde.com · world-today-news.com