CVE-2025-26644

CVSS 3.1 Score 5.1 of 10 (medium)

Details

Published Apr 8, 2025
Updated: Apr 9, 2025
CWE ID 1039

Summary

CVE-2025-26644 is a vulnerability affecting Windows Hello, a biometric authentication system. Hackers can exploit this issue by introducing adversarial input perturbations that bypass the automated recognition mechanism, enabling local spoofing attacks without the user's knowledge. This weakness could lead to unauthorized access to protected systems and data. Users are encouraged to apply security patches and updates as soon as they become available to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows 10
  • Microsoft Windows 11

Affected Vendors

  • Microsoft