SOFTWARE AND UPDATES Microsoft Patches Passkey Flaw CVE-2026-34348 in Windows 11 AMD MSI PRO MAX EDGE AI+ Brings 126 TOPS AI to a 4-Liter Desktop ANDROID Alldocube iPlay 70 Max Pro 4G Launches for $200 with 13-Inch Display XBOX SERIES X Final Fantasy VII Revelation Minigames Get Difficulty Settings and Skip Options STEAM Palworld 1.0 Hits 1 Million Steam Players as Sales Top 30 Million Copies GAMES Final Fantasy 17 Director Rumors: Hamaguchi Hesitation Sparks Speculation NINTENDO Halo: Campaign Evolved Hits PS5, Xbox Series, and PC This Week ACCESSORIES Wallhack K-001 Keyboard Brings Magnetic Switches and 8K Polling AMD Thunderobot 25Q6A Pro 360Hz Mini LED Monitor Launches for $192 ANDROID OnePlus 16 October Launch Tipped With 9,000mAh Battery and 200MP Camera PC HARDWARE COLORFIRE ME26A Cat-Themed PC Case Features Paw Power Button AMD SharpEmu Boots GTA 5 to Loading Screen, PS5 Emulation Milestone PLAYSTATION 5 PS5 Fans Plan Console Blackout to Protest Sony Ending Disc Production PC HARDWARE ASRock Phantom Gaming PGO27QSA QD-OLED Monitor Launches

Microsoft Patches Passkey Flaw CVE-2026-34348 in Windows 11

Owen Carter 0 comments 2 min read

Microsoft patched CVE- 2026- 34348, a passkey reuse vulnerability in Windows 11 and Entra ID, to prevent credential replay attacks in enterprise environments.

Microsoft Patches Passkey Flaw CVE-2026-34348 in Windows 11
SOFTWARE AND UPDATES

Microsoft closed a critical security gap in its passkey infrastructure on July 14. This patch protects enterprise environments from attacks that bypass traditional password requirements. Users relying on FIDO2 keys for single sign-on now have a verified fix for a flaw that allowed credential reuse.

Enterprise identity management requires strict enforcement of modern authentication standards

The vulnerability, tracked as CVE-2026-34348, targeted the interaction between Windows 11 and Microsoft Entra ID. Security researcher Michael Grafnetter demonstrated how an attacker could exploit this setup during a presentation at Black Hat USA. The attack, dubbed 'Pass-the-Passkey,' allowed unauthorized access without the victim's actual password.

Grafnetter found that Windows 11 logged full copies of passkey material, creating a local security risk. Microsoft Entra ID failed to prevent the reuse of these captured keys across different sessions. The cloud-side flaw specifically enabled attackers to replay valid authentication tokens generated by legitimate users.

Microsoft addressed the cloud-side vulnerability on July 14 to stop the token replay attacks. The fix primarily impacts enterprise deployments that use Entra ID for identity management. Organizations should verify that their FIDO2 key implementations are updated to prevent legacy password logins.

Passkeys remain a more secure alternative to passwords when configured correctly. The vulnerability highlights the need for strict enforcement of modern authentication standards. Enterprises must disable legacy password options to fully benefit from the security improvements.

Source: Pass-the-Passkey, NotebookCheck

Discussion

0 comments

Leave a comment