Lenovo Authentication Bypass Vulnerability
A security flaw has been discovered in fingerprint readers used in Lenovo ThinkPad and Notebook models that use Windows Hello authentication with enrolled fingerprints. This flaw could allow attackers with physical access to your device to bypass your fingerprint security and gain full access to your computer.
Solutions and mitigations
Install the latest Windows updates.
For devices with Synaptics or ELAN fingerprint readers
Enable Windows Hello Enhanced Sign-in Security (ESS)
Upgrade to the latest driver version.
For devices with Goodix fingerprint readers
Upgrade to the latest driver version.
Vulnerability Details
CVE-ID: CVE-2024-23592
CVSS3.0 Score: 6.3 (Medium Severity)