SB2020042120 - Information disclosure in WindowsHello library
Published: April 21, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Inadequate Encryption Strength (CVE-ID: CVE-2020-11005)
The vulnerability allows a local attacker to gain access to sensitve information on the target system.
The vulnerability exists due to weak hashing algorithm and insecure permissions. If the library is used to encrypt text and write the output to a txt file, a local attacker can use another executable to decrypt the text using the static method "NCryptDecrypt" from this same library without the need to use Windows Hello Authentication again.
Remediation
Install update from vendor's website.