Windows Hello
by Microsoft
CVEs (13)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-27928 | Hig | 0.57 | 8.7 | 0.00 | Apr 14, 2026 | Improper input validation in Windows Hello allows an unauthorized attacker to bypass a security feature over a network. | ||
| CVE-2023-32018 | Hig | 0.51 | 7.8 | 0.01 | Jun 14, 2023 | Windows Hello Remote Code Execution Vulnerability | ||
| CVE-2026-20852 | Hig | 0.50 | 7.7 | 0.01 | Jan 13, 2026 | Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally. | ||
| CVE-2026-20804 | Hig | 0.50 | 7.7 | 0.01 | Jan 13, 2026 | Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally. | ||
| CVE-2025-53139 | Hig | 0.50 | 7.7 | 0.00 | Oct 14, 2025 | Cleartext transmission of sensitive information in Windows Hello allows an unauthorized attacker to bypass a security feature locally. | ||
| CVE-2025-26635 | Med | 0.42 | 6.5 | 0.01 | Apr 8, 2025 | Weak authentication in Windows Hello allows an authorized attacker to bypass a security feature over a network. | ||
| CVE-2022-35797 | Med | 0.40 | 6.1 | 0.01 | Aug 9, 2022 | Windows Hello Security Feature Bypass Vulnerability | ||
| CVE-2021-42288 | Med | 0.37 | 5.7 | 0.01 | Nov 10, 2021 | Windows Hello Security Feature Bypass Vulnerability | ||
| CVE-2021-34466 | Med | 0.37 | 5.7 | 0.01 | Jul 16, 2021 | Windows Hello Security Feature Bypass Vulnerability | ||
| CVE-2026-61928 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally. | ||
| CVE-2025-26644 | Med | 0.33 | 5.1 | 0.01 | Apr 8, 2025 | Automated recognition mechanism with inadequate detection or handling of adversarial input perturbations in Windows Hello allows an unauthorized attacker to perform spoofing locally. | ||
| CVE-2026-27906 | Med | 0.29 | 4.4 | 0.00 | Apr 14, 2026 | Improper input validation in Windows Hello allows an authorized attacker to bypass a security feature locally. | ||
| CVE-2025-47969 | Med | 0.29 | 4.4 | 0.01 | Jun 10, 2025 | Exposure of sensitive information to an unauthorized actor in Windows Hello allows an authorized attacker to disclose information locally. |
- risk 0.57cvss 8.7epss 0.00
Improper input validation in Windows Hello allows an unauthorized attacker to bypass a security feature over a network.
- risk 0.51cvss 7.8epss 0.01
Windows Hello Remote Code Execution Vulnerability
- risk 0.50cvss 7.7epss 0.01
Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally.
- risk 0.50cvss 7.7epss 0.01
Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally.
- risk 0.50cvss 7.7epss 0.00
Cleartext transmission of sensitive information in Windows Hello allows an unauthorized attacker to bypass a security feature locally.
- risk 0.42cvss 6.5epss 0.01
Weak authentication in Windows Hello allows an authorized attacker to bypass a security feature over a network.
- risk 0.40cvss 6.1epss 0.01
Windows Hello Security Feature Bypass Vulnerability
- risk 0.37cvss 5.7epss 0.01
Windows Hello Security Feature Bypass Vulnerability
- risk 0.37cvss 5.7epss 0.01
Windows Hello Security Feature Bypass Vulnerability
- risk 0.36cvss 5.5epss 0.00
Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally.
- risk 0.33cvss 5.1epss 0.01
Automated recognition mechanism with inadequate detection or handling of adversarial input perturbations in Windows Hello allows an unauthorized attacker to perform spoofing locally.
- risk 0.29cvss 4.4epss 0.00
Improper input validation in Windows Hello allows an authorized attacker to bypass a security feature locally.
- risk 0.29cvss 4.4epss 0.01
Exposure of sensitive information to an unauthorized actor in Windows Hello allows an authorized attacker to disclose information locally.