Threat Advisory

Windows Passkey Flaws Allow Attackers to Impersonate Privileged Users

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A vulnerability in the Windows Event Logging Service, tracked as CVE-2026-34348 with a CVSS score of 6.5, allows an attacker to impersonate privileged users while satisfying phishing-resistant multifactor authentication (MFA) by reusing signed authentication material rather than stealing the authenticator's private key. This flaw is an information-disclosure vulnerability that affects releases across Windows 10, Windows 11, and Windows Server. The issue stems from past YubiKey signatures being stored in cleartext where authenticated unprivileged users could read them, and chaining those signatures with weaknesses in Microsoft Entra ID's passkey validation allowed privileged-user impersonation despite policies requiring phishing-resistant MFA. This vulnerability demonstrates the importance of a least-privilege access approach, using phishing-resistant authentication methods, and maintaining endpoint protections by embracing a Zero Trust security model to be better protected.

RECOMMENDATION:

We recommend you to refer this link: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34348[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A vulnerability in the Windows Event Logging Service, tracked as CVE-2026-34348 with a CVSS score of 6.5, allows an attacker to impersonate privileged users while satisfying phishing-resistant multifactor authentication (MFA) by reusing signed authentication material rather than stealing the authenticator's private key. This flaw is an information-disclosure vulnerability that affects releases across Windows 10, Windows 11, and Windows Server. The issue stems from past YubiKey signatures being stored in cleartext where authenticated unprivileged users could read them, and chaining those signatures with weaknesses in Microsoft Entra ID's passkey validation allowed privileged-user impersonation despite policies requiring phishing-resistant MFA. This vulnerability demonstrates the importance of a least-privilege access approach, using phishing-resistant authentication methods, and maintaining endpoint protections by embracing a Zero Trust security model to be better protected.

RECOMMENDATION:

We recommend you to refer this link: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34348[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu