Research / Advisories

advisory

Windows Hello bypass in Synaptics fingerprint readers on Lenovo ThinkPad

high CVE-2024-23592 · Synaptics

Vendor
Synaptics
Product
Fingerprint reader firmware See Lenovo advisory (LEN-155804) for affected and patched versions
Severity
high
Identifiers
CVE-2024-23592 · GHSA-jvqw-c9fq-fp4h
Published
2024-04-05
Status
✓ fixed

Part of A Touch of Pwn: Bypassing Windows Hello Fingerprint Authentication

A physical attacker can enroll their own fingerprint under a legitimate user’s identity and authenticate to Windows Hello as that user, a complete bypass. Any enrolled user is affected.

Read the full advisory in our advisory database.

Disclosure timeline

  1. noteCVE Issued
  2. fixed

people: Jesse D'Aguanno Timo Teräs

Related

advisory

Windows Hello bypass via sensor spoofing in the ELAN fingerprint sensor

high CVE-2024-0454 · ELAN

A physical attacker can impersonate the sensor with a spoofed USB device and assert that an authorized user has authenticated, bypassing Windows Hello with no valid fingerprint. Any enrolled user is …

✓ fixed Jesse D'Aguanno, Timo Teräs

post

A Touch of Pwn - Part I

TL;DR Microsoft’s Offensive Research and Security Engineering (MORSE) asked us to evaluate the security of the top three fingerprint sensors embedded in laptops and used for Windows Hello fingerprint …

Jesse D'Aguanno, Timo Teräs