Windows Hello for Business Faces New Issue After Security Update | |
A recent Windows security update has led to login failures for some Windows Hello for Business (WHfB) users, Microsoft has confirmed. The patch, part of the April 2025 update (KB5055523), was intended to resolve a critical Kerberos vulnerability (CVE-2025-26647) but has instead disrupted authentication processes. The vulnerability fix targeted an inconsistency in how Windows stored Kerberos certificates. It aimed to ensure only trusted certificates in the NTAuth store were used for authentication, blocking those from the root store. However, this change has caused problems for Active Directory Domain Controllers (DCs) that rely on certificate-based credentials, including WHfB and Machine PKINIT setups. Users have reported login failures, particularly in environments using smart cards, third-party single sign-on (SSO) solutions, and identity management systems. Microsoft confirmed that the bug affects all Windows Server versions from 2016 onwards. For more details please visit our website - https://www.grcviewpoint.com/windows-hello-for-business-faces-new-issue-after-security-update/ ![]() | |
Related Link: Click here to visit item owner's website (0 hit) | |
Target State: New York Target City : New York City Last Update : Oct 11, 2025 6:17 AM Number of Views: 31 | Item Owner : grcviewpoint Contact Email: Contact Phone: + 1 (307) 2432625 |
Friendly reminder: Click here to read some tips. |