
Analysis of Windows Hello for Business Security and Recent Vulnerabilities in Nginx and 7-Zip
On July 17, 2020, the SANS Internet Storm Center StormCast covered a 169-page study by the German Federal Information Security Office analyzing Windows Hello for Business, highlighting security modes like Enhanced Sign-In Security (ESS) that protect biometric data via TPM rather than encrypted files. The study found that biometrics do not increase key entropy compared to a PIN but reduce risk by requiring physical device access for exploitation, while multi-user devices elevate security risks. It also uncovered undocumented features through reverse analysis, filling gaps in Microsoft’s official documentation. Additionally, the episode reported a heap-based buffer overflow vulnerability in Nginx’s map expressions (affecting both Nginx Plus and open-source versions), exploitable for denial-of-service or remote code execution only if ASLR is disabled. A separate heap-based buffer overflow in 7-Zip’s XC decompression, disclosed by the Zero Day Initiative, was patched after coordinated release in early June. The vulnerabilities require specific configurations or disabled security features to be fully exploitable.