Identity

Windows Hello for Business keys can be silently abused by malware

Microsoft March Patch Tuesday roundup

As noted by The Hacker News, a new technique allows malware already running within a signed-in Windows session to silently leverage a victim's Windows Hello for Business key for authentication to Microsoft Entra ID. This bypasses the need for the user's direct interaction or administrator privileges.

Researcher Dirk-jan Mollema demonstrated that malware can exploit Windows Hello for Business keys on TPM-backed systems without extracting private keys, recovering PINs, or triggering biometric prompts. The technique requires code execution within the victim's active session, allowing malicious code to request Windows to sign authentication data. This signed assertion can then be used to obtain a Primary Refresh Token (PRT), register a new device under the attacker's control, and potentially add further authentication methods, even satisfying phishing-resistant authentication requirements. The PRT, valid for 90 days and continuously renewed, grants long-term cloud access.

While not actively exploited in the wild according to the disclosure, the finding highlights a vulnerability where hardware-bound credentials can be invoked by compromised endpoint sessions. Mollema recommends monitoring for unexpected device registrations and Windows Hello for Business sign-ins lacking a device ID claim.

Source: The Hacker News

You can skip this ad in 5 seconds