CVE-2025-26644CWE-1039

Windows Hello Spoofing Vulnerability

Medium · published April 8, 2025

CVSS v3.1
5.1
EPSS
1%
Percentile
43.9
In the wild
Unconfirmed
What it is

Automated recognition mechanism with inadequate detection or handling of adversarial input perturbations in Windows Hello allows an unauthorized attacker to perform spoofing locally.

The record
Technical detail
CVSS v3.1
5.1 · MEDIUM
Vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C
CVSS v4.0
Not supplied
EPSS
0.00549 · 43.9th percentile
Weakness
CWE-1039 · Inadequate Detection or Handling of Adversarial Input Perturbations in Automated Recognition Mechanism
Published
2025-04-08T17:23Z
EPSS history
Timeline
  • 08 APR 17:23Z
    Windows Hello Spoofing Vulnerability
    cvelistv5