
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-11005 is a critical security vulnerability discovered in the WindowsHello C# library versions 1.0.3 and earlier. The vulnerability was disclosed on April 14, 2020, affecting the encryption functionality of the library. The issue allows unauthorized access to encrypted data through the internal NCryptDecrypt method (GitHub Advisory).
The vulnerability exists in the static NCryptDecrypt method implementation, which could be accessed by other executables without requiring Windows Hello Authentication. This means that if the library was used to encrypt text and store it in a file, other applications could potentially decrypt the text using the same method, bypassing the intended authentication mechanism (GitHub Advisory).
The vulnerability allows unauthorized decryption of data that was intended to be protected by Windows Hello authentication. Any application using the affected library versions could have their encrypted data exposed to unauthorized access, effectively bypassing the security measures intended by the Windows Hello authentication system (GitHub Advisory).
The vulnerability has been patched in version 1.0.4 and later versions of the WindowsHello library. Users are strongly advised to upgrade to the latest version. No workarounds are available for earlier versions (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."