Description
An authentication bypass vulnerability was reported in Lenovo devices with Synaptics fingerprint readers that could allow an attacker with physical access to replay fingerprints and bypass Windows Hello authentication.
No analysis available yet.
Remediation
Vendor Solution
Enable Windows Hello Enhanced Sign-in Security (ESS) and upgrade to the driver version (or newer) indicated for your model in the advisory: https://support.lenovo.com/us/en/product_security/LEN-155804
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-21086 | An authentication bypass vulnerability was reported in Lenovo devices with Synaptics fingerprint readers that could allow an attacker with physical access to replay fingerprints and bypass Windows Hello authentication. |
References
| Link | Providers |
|---|---|
| https://support.lenovo.com/us/en/product_security/LEN-155804 |
|
History
No history.
Subscriptions
No data.
Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2024-09-06T20:09:15.535Z
Reserved: 2024-01-18T15:28:42.477Z
Link: CVE-2024-23592
Updated: 2024-08-01T23:06:25.249Z
Status : Awaiting Analysis
Published: 2024-04-05T21:15:08.450
Modified: 2024-11-21T08:57:58.270
Link: CVE-2024-23592
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD