Horizon Alert
Summary of the vulnerability and why it matters
This advisory concerns a critical vulnerability in on-premises deployments that could allow an attacker to register a malicious credential and then impersonate a legitimate user. The issue bypasses standard authentication mechanisms, potentially leading to unauthorized access and control of targeted accounts.
- Attackers can impersonate users with stolen credentials.
- Critical access risk if on-premises systems are exposed.
- Confirm relevance; on-premises deployments are the focus.
Attack Path
How an attacker could exploit the issue
An attacker could target an organization's on-premises systems to register a fraudulent FIDO2 credential associated with a legitimate user account. Once registered, this malicious credential could be used to authenticate as the targeted user, granting the attacker access to their account. This vulnerability could potentially allow an attacker to gain unauthorized access and control over user accounts within the affected on-premises environment.
- No authentication or special privileges are needed.
- Registering a malicious FIDO2 credential.
- Unauthorized account access and control.
Live Threat
Current exploitation, exposure, and threat context
Under specific conditions in on-premises deployments, an attacker could register a fraudulent FIDO2 credential to impersonate a targeted user, potentially leading to unauthorized access.
- Target account credentials.
- Attacker registers malicious FIDO2 credential.
- Unauthorized account access may occur.
Operational Fix
Recommended remediation, mitigation, and detection steps
Given this vulnerability affects only on-premises deployments, the primary responsibility for remediation likely falls to infrastructure or platform teams, in conjunction with application owners who manage the target accounts. The initial, critical step is to inventory all on-premises systems where the affected technology is deployed, determine their business criticality and external reachability, and identify the accountable system owner. This will inform a risk-based remediation plan, coordinating efforts to mitigate the threat.
- Application and infrastructure teams own remediation.
- Verify on-premises deployment and account reachability.
- Plan and execute remediation based on risk.