Microsoft Releases Security Advisory for Windows Hello for Business
Microsoft has released a security advisory to address an issue in Windows Hello for Business (WHfB). An attacker could exploit this issue on devices that were affected by CVE-2017-15361, also known as Return of Coppersmith’s Attack (ROCA), to take control of an affected system.
Summary
Microsoft has released a security advisory to address an issue in Windows Hello for Business (WHfB). An attacker could exploit this issue on devices that were affected by CVE-2017-15361, also known as Return of Coppersmith’s Attack (ROCA), to take control of an affected system.
Affected platforms
The following platforms are known to be affected:
- All platforms and products affected by CVE-2017-15361. Please see RSA Encryption Key Vulnerability CC-1706 for further details.
Threat details
For further information:
- CVE-2017-15361 - CVSS v3 5.9
- Microsoft Security Advisory ADV170012
Remediation steps
| Type | Step |
|---|---|
|
Users and administrators are encouraged to review Microsoft security advisory ADV190026 and apply the recommended mitigations. |
CVE Vulnerabilities
Last edited: 29 June 2021 11:57 am