FB pixel

Security researchers find biometrics vulnerability in Windows Hello for Business

Security researchers find biometrics vulnerability in Windows Hello for Business
 

Organizations are increasingly turning to biometrics to secure their corporate networks and assets, but German cybersecurity researchers have found what they say is a flaw in the implementation of Windows Hello for Business that could make it vulnerable to bypass attacks.

Dr. Baptiste David and Tillmann Osswald of ERNW Research told an audience at the Black Hat conference in Las Vegas that a code injection attack can enable a biometric injection attack from another PC that would compromise biometric authentication, granting access  to any face or fingerprint submitted.

Business users authenticate with Windows Hello to access company servers through digital identity and access management (IAM) platforms like Entra ID or Active Directory.

The attack works by identifying information within the CryptProtectData software that secures the database containing the cryptographic key linked to the Windows Biometric Service to break the encryption. Microsoft provides Enhanced Sign-in Security (ESS) software, which blocks the attack from its hypervisor virtual trust level (VTL1) by default. But not all PCs support ESS.

Tillman told The Register that PCs that do not use Intel chips may not have a secure camera sensor, so cannot use ESS.

Osswald describes the attack process in-depth in a recent blog post. A June post details how Hello authentication works, along with previously discovered attacks on Windows Hello for Business.

Potential fixes could involve storing biometric data in the Trusted Platform Module (TPM), or a major code rewrite.

Their findings come from a two-year research program, Windows Dissect, which is intended to uncover security flaws in the world’s most popular desktop OS, and is supported by Germany’s Federal Office for Information Security (BSI).

Related Posts

Article Topics

 |   |   |   |   |   | 

Latest Biometrics News

 

CLEAR brings biometric identity checks to Mount Sinai hospitals amid privacy scrutiny

Clear Secure Inc., the biometrics company that made its name speeding travelers through airport lines, is pushing deeper into health…

 

Cybernetica, Tony Blair Institute pilot digital credential wallet in Kenya

A proof-of-concept to implement a verifiable credentials (VC) system to fight a growing wave of academic and public service recruitment…

 

Biometrics back digital government gains around the world

Digital government was in the spotlight this week on Biometric Update with the release of the OECD rankings and a…

 

MOSIP delves into biometric data quality considerations

Biometric data quality was in focus at MOSIP Connect 2026 in Rabat, Morocco, from policies for ensuring good enrollment practices…

 

NIST nominee pressed on AI standards, facial recognition oversight

The Senate Committee on Commerce, Science and Transportation on Thursday considered the nomination of Arvind Raman to serve as Under…

 

Trulioo’s Hal Lonas on how he applies aeronautics principles to fighting fraud

Rocket science is routinely held up as the ultimate example of a highly complex discipline. But Trulioo’s Hal Lonas found…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events