SB2020042120 - Information disclosure in WindowsHello library



SB2020042120 - Information disclosure in WindowsHello library

Published: April 21, 2020

Security Bulletin ID SB2020042120
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Inadequate Encryption Strength (CVE-ID: CVE-2020-11005)

The vulnerability allows a local attacker to gain access to sensitve information on the target system.

The vulnerability exists due to weak hashing algorithm and insecure permissions. If the library is used to encrypt text and write the output to a txt file, a local attacker can use another executable to decrypt the text using the static method "NCryptDecrypt" from this same library without the need to use Windows Hello Authentication again.


Remediation

Install update from vendor's website.