← back
CVE-2025-26635

Windows Hello Security Feature Bypass Vulnerability

CVSS 6.5 MEDIUMEPSS 1.3%CWE-1390
In short

Windows Hello, Windows' facial recognition and fingerprint login system, has a weakness that allows someone with network access to bypass its security protections. This means an attacker could potentially log in as another user without proper authentication.

Technical detail

A weak authentication implementation in Windows Hello enables an authorized network attacker to circumvent the security feature, likely through replay attacks or improper validation of authentication tokens. Exploitation requires network-level access and valid initial authentication credentials to the system.

Summary generated and translated by AI from the official description.
Weak authentication in Windows Hello allows an authorized attacker to bypass a security feature over a network.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →