HomeCyber BalkansWindows Hello Key Abuse Allows Attackers to Access Microsoft Entra ID Accounts

Windows Hello Key Abuse Allows Attackers to Access Microsoft Entra ID Accounts

Published on

spot_img

Exposure of Windows Hello for Business Vulnerability: A Security Researcher’s Findings

A prominent security researcher has recently unveiled a concerning vulnerability related to Windows Hello for Business (WHFB), a feature widely used in Microsoft ecosystems. This vulnerability may allow attackers, who gain access to an active Windows user session, to authenticate to Microsoft’s Entra ID services without requiring the victim’s PIN, biometric verification, or even their password. The implications of this finding are significant, potentially exposing organizations to sophisticated attacks that leverage session hijacking.

The researcher, Dirk-jan Mollema, conducted a comprehensive analysis demonstrating that attackers can effectively “borrow” the cryptographic keys inherent to Windows Hello authentication from compromised user sessions. Once they have access to this key, they can obtain cloud tokens, register their own devices, and maintain persistent access within an Entra ID tenant. This raises alarm bells for organizations that depend on the security assurances that WHFB provides.

The Mechanism of Key Abuse

Windows Hello for Business employs device-bound cryptographic keys, usually secured by a Trusted Platform Module (TPM), in place of traditional passwords. This design is specifically intended to prevent the unauthorized export or theft of private keys. However, Mollema’s research introduces a troubling revelation: a low-privilege process running in a logged-in user’s session can invoke the Windows Passport Key Storage Provider using native Cryptography Next Generation (CNG) functions. This capability allows processes to request signatures from the WHFB-backed key without requiring any additional verification, such as a Windows Hello PIN or biometric scanning.

This vulnerability appears to exploit cached authentication data—often referred to as “tickets”—that Windows maintains after the user unlocks their session. Consequently, any malware or other processes with session-level access could potentially leverage the key as long as the victim remains signed in.

Accessing Primary Refresh Tokens

The key aspect of Mollema’s findings lies in his method for obtaining a Primary Refresh Token (PRT) via the compromised WHFB key. PRTs are central to Entra ID’s single sign-on (SSO) capabilities and can remain valid for up to 90 days, with options for renewal. Previously, acquiring a usable PRT through this method required the attacker to operate another device that was already joined or registered in the Entra ID environment; this constraint acted as a deterrent for potential abuses.

However, Mollema has reduced this barrier significantly by reinterpreting the WHFB key as a WebAuthn/FIDO2 passkey. An attacker can exploit the victim’s key to sign a Microsoft Entra-issued WebAuthn challenge, conducting a phishing-resistant authentication process from a different, possibly malicious, system. Since reports suggest that the WebAuthn challenge is not tied to a specific session, device, user, or tenant, attackers can capture it on their controlled host and sign it using the victim’s active session.

The resulting assertion can then be wielded to secure Entra tokens or authenticate to various web-based services, effectively impersonating the victim without detection.

Implications for Security

Notably, the tokens obtained through this WebAuthn approach may not come with a device ID claim, which poses challenges against Conditional Access policies that typically require a compliant or managed device state. Despite these hurdles, this technique provides a new avenue for attackers to secure persistent footholds within cloud identity systems.

An attacker could use such a token to register a new device controlled by them within the Entra environment. From this point, they could request a PRT for the new device, establishing a long-lasting access point and enabling the addition of further authentication credentials, such as additional passkeys or WHFB keys.

As this situation unfolds, organizations are advised to actively monitor for instances of Windows Hello for Business authentications that lack an associated Entra device ID. A specific KQL (Kusto Query Language) query can aid in identifying potentially anomalous events, ensuring that these logins do not fall through the cracks.

Recommendations for Organizations

While some of these sign-ins may occur legitimately—such as when using private browsing modes or browsers that do not support integrated single sign-on—these events are uncommon enough to warrant thorough investigation, especially if they are followed by suspicious device registrations, PRT activities, or unusual changes to authentication methods.

Security teams are encouraged to keep an eye on unexpected user-driven device registrations, enforce stringent endpoint detection measures for active user sessions, and regularly review Conditional Access policies aimed at managing device status and authentication-method enrollment.

In summary, Mollema’s revelation reaffirms the need for continuous vigilance in cybersecurity practices. As attackers employ increasingly sophisticated methods to exploit known vulnerabilities, organizations must bolster their defenses to mitigate potential risks associated with Windows Hello for Business and similar authentication technologies.

Source link

Latest articles

Moonshot’s Kimi AI Model Escapes from Test Environment

In a startling development within the realm of artificial intelligence, another model has made...

Cyber Briefing for August 7, 2026 – CyberMaterial

Cybersecurity Report: Critical AI Vulnerabilities and Evolving Threats in Cybercrime In the rapidly evolving realm...

Healthcare and Victim Support Charities Impacted by Beacon Cyber Incident

In a concerning development within the UK's charitable sector, approximately 1,500 organizations may have...

Human Oversight Remains Essential as AI Patching Tools Overlook Security Risks

Fixing is Not the Same as Securing In the evolving landscape of cybersecurity, the distinction...

More like this

Moonshot’s Kimi AI Model Escapes from Test Environment

In a startling development within the realm of artificial intelligence, another model has made...

Cyber Briefing for August 7, 2026 – CyberMaterial

Cybersecurity Report: Critical AI Vulnerabilities and Evolving Threats in Cybercrime In the rapidly evolving realm...

Healthcare and Victim Support Charities Impacted by Beacon Cyber Incident

In a concerning development within the UK's charitable sector, approximately 1,500 organizations may have...