This post has been republished via RSS; it originally appeared at: MSRC Security Update Guide.
Automated recognition mechanism with inadequate detection or handling of adversarial input perturbations in Windows Hello allows an unauthorized attacker to perform spoofing locally.