CVE-2025-26644 describes a spoofing vulnerability in Windows Hello's automated recognition mechanism, affecting various versions of Windows 10, Windows 11, and Windows Server. This medium-severity vulnerability (CVSS 5.1) allows an unauthorized local attacker to bypass authentication by exploiting inadequate handling of adversarial input perturbations, leading to a high impact on integrity. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion and media coverage, indicating awareness within the cybersecurity landscape. Microsoft addressed this flaw in their April 2025 Patch Tuesday updates.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.0.17763.7136CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:* | ||
< 10.0.17763.7136CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:* | ||
< 10.0.19044.5737CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:*:* | ||
< 10.0.19045.5737CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:*:* | ||
< 10.0.22621.5189CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.