← back
CVE-2025-26635mediumCWE-1390

Windows Hello Security Feature Bypass Vulnerability

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6.5epss 1.5%
exploitation probability
1.5%top 28% of all CVEs
observed exploitation
nono source reports it
In short

Windows Hello, Windows' facial recognition and fingerprint login system, has a weakness that allows someone with network access to bypass its security protections. This means an attacker could potentially log in as another user without proper authentication.

Technical detail

A weak authentication implementation in Windows Hello enables an authorized network attacker to circumvent the security feature, likely through replay attacks or improper validation of authentication tokens. Exploitation requires network-level access and valid initial authentication credentials to the system.

Summary generated and translated by AI from the official description.
Weak authentication in Windows Hello allows an authorized attacker to bypass a security feature over a network.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C