Urgent.News

600+ sources. One page. See who else covered it.

Editions

Tech

Windows Hello flaw opens path to Entra access

A Windows Hello for Business authentication technique can allow malware operating inside an unlocked Windows session to gain access to Microsoft Entra ID services without obtaining the user’s password, PIN or biometric data. Security researcher Dirk-jan Mollema demonstrated that an attacker who already controls a user process can invoke the cryptographic key underpinning Windows Hello for…

A security researcher discovered a flaw in Windows Hello for Business authentication that could allow malware running within an unlocked Windows session to gain access to Microsoft Entra ID services without the user's password or biometric data. This vulnerability enables an attacker who already controls a user process to use the cryptographic key underlying Windows Hello for Business to generate authentication signatures, effectively "borrowing" the key.

The compromised key can then be used to create a signed WebAuthn assertion, enabling the attacker to authenticate to Entra ID using the victim's Windows Hello credential as a FIDO2-style passkey. The authentication process is not bound to a specific device, session, or user, allowing the attacker to initiate part of the authentication process on another machine and have the victim's Windows Hello key sign it.

As a result, tokens obtained through this method may lack a device ID, potentially enabling the attacker to register a new device under their control during subsequent authentication attempts. Despite the lack of remote compromise, endpoint compromise is still required as the initial security boundary. The flaw does not directly exploit the hardware-protected secret, and detection may require organizations to examine Entra sign-in logs for Windows Hello for Business authentications where the device ID is empty, although such events may be legitimate in certain scenarios.

Written by urgent.news from Arabian Post's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at thearabianpost.com →

More in Tech

More from Friday 7 August →