Research / Advisories

advisory

Windows Hello bypass via sensor spoofing in the ELAN fingerprint sensor

high CVE-2024-0454 · ELAN

Vendor
ELAN
Product
Match-on-Chip fingerprint sensor driver and firmware < Driver: 3.0.12011.08009 (Legacy) / 3.3.12011.08103 (ESS)
Severity
high
Identifiers
CVE-2024-0454 · GHSA-3q6q-g6q7-wvj8
Published
2024-01-12
Status
✓ fixed

Part of A Touch of Pwn: Bypassing Windows Hello Fingerprint Authentication

A physical attacker can impersonate the sensor with a spoofed USB device and assert that an authorized user has authenticated, bypassing Windows Hello with no valid fingerprint. Any enrolled user is affected.

Read the full advisory in our advisory database.

Disclosure timeline

  1. noteCVE Assignment

people: Jesse D'Aguanno Timo Teräs

Related

post

A Touch of Pwn - Part I

TL;DR Microsoft’s Offensive Research and Security Engineering (MORSE) asked us to evaluate the security of the top three fingerprint sensors embedded in laptops and used for Windows Hello fingerprint …

Jesse D'Aguanno, Timo Teräs