Microsoft Windows Hello for Business Vulnerable to 'Face Swap Attack', Enabling Disguised Logins via 'Face Replacement'
1 day ago / Read about 0 minute
Author:小编   

Security research firm ERNW has unveiled a critical vulnerability in Windows Hello for Business, termed the 'Face Swap Attack'. With administrative privileges, attackers can decrypt and manipulate biometric data, facilitating disguised logins by substituting user identities. This vulnerability stems from the fact that Windows Hello does not directly employ biometric data for authentication, with its encryption keys anchored on locally stored information. ERNW has alerted Microsoft to this vulnerability but anticipates that resolving it will be intricate due to the extensive system architecture adjustments required.