Identix BioLogon Client Biometric Authentication Bypass Vulnerability
BID:3140
Info
Identix BioLogon Client Biometric Authentication Bypass Vulnerability
| Bugtraq ID: | 3140 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 02 2001 12:00AM |
| Updated: | Aug 02 2001 12:00AM |
| Credit: | This vulnerability was submitted to BugTraq on August 2nd, 2001 by Marc DeBonis <[email protected]>. |
| Vulnerable: |
Identix BioLogon Client 2.0.3 Identix BioLogon Client 2.0.2 Identix BioLogon Client 2.0.1 Identix BioLogon Client 2.0 |
| Not Vulnerable: | |
Discussion
Identix BioLogon Client Biometric Authentication Bypass Vulnerability
Identix BioLogon Client is a software utility which provides support for biometric security measures(fingerprint readers, smartcards, etc.) on Microsoft Windows systems. Part of its design is to help restrict unauthorized users from physically accessing the host.
BioLogin does not protect systems with multi-monitor support. The BioLogon Client will attempt to trigger biometric authentication measures when users attempt to unlock the screensaver and gain physical access to the host.
However, biometric security will not attempt to authenticate users who access the host from virtual desktops(ie: screens on other monitors).
It is reported that BioLogon Client on Windows 98 and ME with multi-monitor support enabled, are vulnerable to this issue.
Identix BioLogon Client is a software utility which provides support for biometric security measures(fingerprint readers, smartcards, etc.) on Microsoft Windows systems. Part of its design is to help restrict unauthorized users from physically accessing the host.
BioLogin does not protect systems with multi-monitor support. The BioLogon Client will attempt to trigger biometric authentication measures when users attempt to unlock the screensaver and gain physical access to the host.
However, biometric security will not attempt to authenticate users who access the host from virtual desktops(ie: screens on other monitors).
It is reported that BioLogon Client on Windows 98 and ME with multi-monitor support enabled, are vulnerable to this issue.