advisory
Windows Hello bypass via sensor spoofing in the ELAN fingerprint sensor
- Vendor
- ELAN
- Product
- Match-on-Chip fingerprint sensor driver and firmware < Driver: 3.0.12011.08009 (Legacy) / 3.3.12011.08103 (ESS)
- Severity
- high
- Identifiers
- CVE-2024-0454 · GHSA-3q6q-g6q7-wvj8
- Published
- 2024-01-12
- Status
- ✓ fixed
Part of A Touch of Pwn: Bypassing Windows Hello Fingerprint Authentication
A physical attacker can impersonate the sensor with a spoofed USB device and assert that an authorized user has authenticated, bypassing Windows Hello with no valid fingerprint. Any enrolled user is affected.
Read the full advisory in our advisory database.
Disclosure timeline
- noteCVE Assignment
people: Jesse D'Aguanno Timo Teräs
