CVE-2025-26644CWE-1039
Windows Hello Spoofing Vulnerability
Medium · published April 8, 2025
What it is
Automated recognition mechanism with inadequate detection or handling of adversarial input perturbations in Windows Hello allows an unauthorized attacker to perform spoofing locally.
The record
Technical detail
- CVSS v3.1
- 5.1 · MEDIUM
- Vector
- CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C
- CVSS v4.0
- Not supplied
- EPSS
- 0.00549 · 43.9th percentile
- Weakness
- CWE-1039 · Inadequate Detection or Handling of Adversarial Input Perturbations in Automated Recognition Mechanism
- Published
- 2025-04-08T17:23Z
EPSS history
Timeline