CVE-2020-11005: Use of a Broken or Risky Cryptographic Algorithm
(updated )
The WindowsHello has a vulnerability where encrypted data could potentially be decrypted without needing authentication. If the library is used to encrypt text and write the output to a txt file, another executable could be able to decrypt the text using the static method NCryptDecrypt
from this same library without the need to use Windows Hello Authentication again.
References
Detect and mitigate CVE-2020-11005 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →