mimile
mimile.ai
Back to feed

SpecterOps to unveil passkey flaws at Black Hat USA

AI digest

This digest was compiled by AI from multiple sources — links to the originals are below.

SpecterOps to unveil passkey flaws at Black Hat USA

SpecterOps researchers will present three zero-day vulnerabilities in Microsoft's passkey implementation at Black Hat USA next month in Las Vegas. The flaws could allow attackers to impersonate privileged cloud identities by replaying authentication credentials.

The Vulnerabilities

Michael Grafnetter, principal security researcher at SpecterOps, discovered three nearly exploitable zero-day vulnerabilities in Windows 11 and Microsoft Entra ID. Two of them form a replay chain dubbed 'Pass-the-Passkey,' which mirrors techniques like pass-the-hash and NTLM Relay. Windows 11 writes a complete copy of the digital key to the event log, and Entra ID fails to prevent reuse of those assertions.

Passkey Adoption Context

Microsoft announced that starting Sept. 1, passkeys will become the default authentication method for Microsoft Entra ID sign-in. Passkeys are considered phishing-resistant and use private keys, making them largely unaffected by data breaches. However, Grafnetter notes that flawed implementation can reintroduce replay, relay, and phishing-like attack paths even with sound WebAuthn cryptography.

What's Next

The research will be presented at Black Hat USA in Las Vegas next month. It remains unclear whether Microsoft will patch the vulnerabilities before the conference or if the flaws affect other passkey implementations.

1 source

SpecterOps to unveil passkey flaws at Black Hat USA