logo

Goodbye? Attackers Can Bypass 'Windows Hello' Strong Authentication

ID: d84aa304-f311-55d9-9831-2164e6554d14

STIX ID: report--d84aa304-f311-55d9-9831-2164e6554d14

Feed Name: Dark Reading

Threat Score
55/100

Date Published: 2024-07-23

Date Updated: 2026-04-21

Author: Jeffrey Schwartz, Contributing Writer

...
...

Accenture researcher Yehuda Smirnov disclosed a downgrade vulnerability in Windows Hello for Business where an adversary-in-the-middle can intercept and modify POST requests (e.g., to "/common/GetCredentialType") or user-agent/isFidoSupported parameters to force a fallback from phishing-resistant authentication (TPM-backed biometric/PIN) to phishable methods; the technique was automated with Evilginx and a phishlet. Microsoft mitigated the issue by adding an "authentication strength" Conditional Access capability allowing administrators to require strictly phishing-resistant methods.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.