CVE-2020-11005
Summary
| CVE | CVE-2020-11005 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-04-14 23:15:00 UTC |
| Updated | 2020-04-22 18:40:00 UTC |
| Description | The WindowsHello open source library (NuGet HaemmerElectronics.SeppPenner.WindowsHello), before version 1.0.4, has a vulnerability where encrypted data could potentially be decrypted without needing authentication. If the library is used to encrypt text and write the output to a txt file, another executable could be able to decrypt the text using the static method NCryptDecrypt from this same library without the need to use Windows Hello Authentication again. This has been patched in version 1.0.4. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [Question] Security of the Encrypted data · Issue #3 · SeppPenner/WindowsHello · GitHub |
MISC |
github.com |
Issue Tracking, Third Party Advisory |
| Internal NCryptDecrypt method could be used by other libraries as well. · Advisory · SeppPenner/WindowsHello · GitHub |
CONFIRM |
github.com |
Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 983126 Dotnet (nuget) Security Update for HaemmerElectronics.SeppPenner.WindowsHello (GHSA-wvpv-ffcv-r6cw)