VYPR

Windows Hello

by Microsoft

CVEs (22)

  • CVE-2026-69784HigSep 8, 2026
    risk 0.57cvss 8.8epss 0.00

    Use after free in Windows Hello allows an authorized attacker to elevate privileges locally.

  • CVE-2026-69740HigSep 8, 2026
    risk 0.57cvss 8.8epss 0.00

    Use after free in Windows Hello allows an authorized attacker to elevate privileges locally.

  • CVE-2026-27928HigApr 14, 2026
    risk 0.57cvss 8.7epss 0.01

    Improper input validation in Windows Hello allows an unauthorized attacker to bypass a security feature over a network.

  • CVE-2026-81354HigSep 8, 2026
    risk 0.53cvss 8.2epss 0.00

    Heap-based buffer overflow in Windows Hello allows an authorized attacker to elevate privileges locally.

  • CVE-2026-69820HigSep 8, 2026
    risk 0.53cvss 8.2epss 0.00

    Heap-based buffer overflow in Windows Hello allows an authorized attacker to elevate privileges locally.

  • CVE-2026-69864HigSep 8, 2026
    risk 0.51cvss 7.8epss 0.00

    Use after free in Windows Hello allows an authorized attacker to elevate privileges locally.

  • CVE-2026-69799HigSep 8, 2026
    risk 0.51cvss 7.8epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hello allows an authorized attacker to elevate privileges locally.

  • CVE-2026-69725HigSep 8, 2026
    risk 0.51cvss 7.8epss 0.00

    Double free in Windows Hello allows an authorized attacker to elevate privileges locally.

  • CVE-2023-32018HigJun 14, 2023
    risk 0.51cvss 7.8epss 0.01

    Windows Hello Remote Code Execution Vulnerability

  • CVE-2026-20852HigJan 13, 2026
    risk 0.50cvss 7.7epss 0.01

    Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally.

  • CVE-2026-20804HigJan 13, 2026
    risk 0.50cvss 7.7epss 0.01

    Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally.

  • CVE-2025-53139HigOct 14, 2025
    risk 0.50cvss 7.7epss 0.00

    Cleartext transmission of sensitive information in Windows Hello allows an unauthorized attacker to bypass a security feature locally.

  • CVE-2026-69710HigSep 8, 2026
    risk 0.49cvss 7.5epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hello allows an authorized attacker to elevate privileges locally.

  • CVE-2025-26635MedApr 8, 2025
    risk 0.42cvss 6.5epss 0.01

    Weak authentication in Windows Hello allows an authorized attacker to bypass a security feature over a network.

  • CVE-2022-35797MedAug 9, 2022
    risk 0.40cvss 6.1epss 0.01

    Windows Hello Security Feature Bypass Vulnerability

  • CVE-2021-42288MedNov 10, 2021
    risk 0.37cvss 5.7epss 0.01

    Windows Hello Security Feature Bypass Vulnerability

  • CVE-2021-34466MedJul 16, 2021
    risk 0.37cvss 5.7epss 0.01

    Windows Hello Security Feature Bypass Vulnerability

  • CVE-2026-61928MedAug 11, 2026
    risk 0.36cvss 5.5epss 0.00

    Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally.

  • CVE-2025-26644MedApr 8, 2025
    risk 0.33cvss 5.1epss 0.01

    Automated recognition mechanism with inadequate detection or handling of adversarial input perturbations in Windows Hello allows an unauthorized attacker to perform spoofing locally.

  • CVE-2026-72980MedSep 8, 2026
    risk 0.29cvss 4.4epss 0.01

    Uncontrolled search path element in Windows Hello allows an authorized attacker to bypass a security feature locally.

Page 1 of 2