advisory
Windows Hello bypass in Synaptics fingerprint readers on Lenovo ThinkPad
- Vendor
- Synaptics
- Product
- Fingerprint reader firmware See Lenovo advisory (LEN-155804) for affected and patched versions
- Severity
- high
- Identifiers
- CVE-2024-23592 · GHSA-jvqw-c9fq-fp4h
- Published
- 2024-04-05
- Status
- ✓ fixed
Part of A Touch of Pwn: Bypassing Windows Hello Fingerprint Authentication
A physical attacker can enroll their own fingerprint under a legitimate user’s identity and authenticate to Windows Hello as that user, a complete bypass. Any enrolled user is affected.
Read the full advisory in our advisory database.
Disclosure timeline
- noteCVE Issued
- fixed
people: Jesse D'Aguanno Timo Teräs
