← Back

CVE-2025-26644

nvd nist
Published: Apr 8, 2025Modified: Jun 17, 2026

JSON object

Loading...
5.1
Vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitability: 1.4 / Impact: 3.6
Source: secure@microsoft.com (Secondary)

Description

Automated recognition mechanism with inadequate detection or handling of adversarial input perturbations in Windows Hello allows an unauthorized attacker to perform spoofing locally.

Affected (9)

8 products
Windows 10 1809
Windows 10 21h2
Windows 10 22h2
Windows 11 22h2
Windows 11 23h2
Windows 11 24h2
Windows Server 2019
Windows Server 2025
Configuration A
9 vulnerable
Vulnerable SoftwareAffected Versions
Microsoft
Before 10.0.17763.7136
Before 10.0.17763.7136
Before 10.0.19044.5737
Before 10.0.19045.5737
Before 10.0.22621.5189
Before 10.0.22631.5189
Before 10.0.26100.3775
Before 10.0.17763.7136
Before 10.0.26100.3775

References (1)

Timeline

No history available yet.