Microsoft closed a critical security gap in its passkey infrastructure on July 14. This patch protects enterprise environments from attacks that bypass traditional password requirements. Users relying on FIDO2 keys for single sign-on now have a verified fix for a flaw that allowed credential reuse.
Enterprise identity management requires strict enforcement of modern authentication standards
The vulnerability, tracked as CVE-2026-34348, targeted the interaction between Windows 11 and Microsoft Entra ID. Security researcher Michael Grafnetter demonstrated how an attacker could exploit this setup during a presentation at Black Hat USA. The attack, dubbed 'Pass-the-Passkey,' allowed unauthorized access without the victim's actual password.
Grafnetter found that Windows 11 logged full copies of passkey material, creating a local security risk. Microsoft Entra ID failed to prevent the reuse of these captured keys across different sessions. The cloud-side flaw specifically enabled attackers to replay valid authentication tokens generated by legitimate users.
Microsoft addressed the cloud-side vulnerability on July 14 to stop the token replay attacks. The fix primarily impacts enterprise deployments that use Entra ID for identity management. Organizations should verify that their FIDO2 key implementations are updated to prevent legacy password logins.
Passkeys remain a more secure alternative to passwords when configured correctly. The vulnerability highlights the need for strict enforcement of modern authentication standards. Enterprises must disable legacy password options to fully benefit from the security improvements.
Source: Pass-the-Passkey, NotebookCheck




Discussion
0 comments