Windows Hello
by Microsoft
CVEs (22)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-69784 | Hig | 0.57 | 8.8 | 0.00 | Sep 8, 2026 | Use after free in Windows Hello allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-69740 | Hig | 0.57 | 8.8 | 0.00 | Sep 8, 2026 | Use after free in Windows Hello allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-27928 | Hig | 0.57 | 8.7 | 0.01 | Apr 14, 2026 | Improper input validation in Windows Hello allows an unauthorized attacker to bypass a security feature over a network. | ||
| CVE-2026-81354 | Hig | 0.53 | 8.2 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Windows Hello allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-69820 | Hig | 0.53 | 8.2 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Windows Hello allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-69864 | Hig | 0.51 | 7.8 | 0.00 | Sep 8, 2026 | Use after free in Windows Hello allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-69799 | Hig | 0.51 | 7.8 | 0.00 | Sep 8, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hello allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-69725 | Hig | 0.51 | 7.8 | 0.00 | Sep 8, 2026 | Double free in Windows Hello allows an authorized attacker to elevate privileges locally. | ||
| CVE-2023-32018 | Hig | 0.51 | 7.8 | 0.01 | Jun 14, 2023 | Windows Hello Remote Code Execution Vulnerability | ||
| CVE-2026-20852 | Hig | 0.50 | 7.7 | 0.01 | Jan 13, 2026 | Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally. | ||
| CVE-2026-20804 | Hig | 0.50 | 7.7 | 0.01 | Jan 13, 2026 | Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally. | ||
| CVE-2025-53139 | Hig | 0.50 | 7.7 | 0.00 | Oct 14, 2025 | Cleartext transmission of sensitive information in Windows Hello allows an unauthorized attacker to bypass a security feature locally. | ||
| CVE-2026-69710 | Hig | 0.49 | 7.5 | 0.00 | Sep 8, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hello allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-26635 | Med | 0.42 | 6.5 | 0.01 | Apr 8, 2025 | Weak authentication in Windows Hello allows an authorized attacker to bypass a security feature over a network. | ||
| CVE-2022-35797 | Med | 0.40 | 6.1 | 0.01 | Aug 9, 2022 | Windows Hello Security Feature Bypass Vulnerability | ||
| CVE-2021-42288 | Med | 0.37 | 5.7 | 0.01 | Nov 10, 2021 | Windows Hello Security Feature Bypass Vulnerability | ||
| CVE-2021-34466 | Med | 0.37 | 5.7 | 0.01 | Jul 16, 2021 | Windows Hello Security Feature Bypass Vulnerability | ||
| CVE-2026-61928 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally. | ||
| CVE-2025-26644 | Med | 0.33 | 5.1 | 0.01 | Apr 8, 2025 | Automated recognition mechanism with inadequate detection or handling of adversarial input perturbations in Windows Hello allows an unauthorized attacker to perform spoofing locally. | ||
| CVE-2026-72980 | Med | 0.29 | 4.4 | 0.01 | Sep 8, 2026 | Uncontrolled search path element in Windows Hello allows an authorized attacker to bypass a security feature locally. |
- risk 0.57cvss 8.8epss 0.00
Use after free in Windows Hello allows an authorized attacker to elevate privileges locally.
- risk 0.57cvss 8.8epss 0.00
Use after free in Windows Hello allows an authorized attacker to elevate privileges locally.
- risk 0.57cvss 8.7epss 0.01
Improper input validation in Windows Hello allows an unauthorized attacker to bypass a security feature over a network.
- risk 0.53cvss 8.2epss 0.00
Heap-based buffer overflow in Windows Hello allows an authorized attacker to elevate privileges locally.
- risk 0.53cvss 8.2epss 0.00
Heap-based buffer overflow in Windows Hello allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Use after free in Windows Hello allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hello allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Double free in Windows Hello allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.01
Windows Hello Remote Code Execution Vulnerability
- risk 0.50cvss 7.7epss 0.01
Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally.
- risk 0.50cvss 7.7epss 0.01
Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally.
- risk 0.50cvss 7.7epss 0.00
Cleartext transmission of sensitive information in Windows Hello allows an unauthorized attacker to bypass a security feature locally.
- risk 0.49cvss 7.5epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hello allows an authorized attacker to elevate privileges locally.
- risk 0.42cvss 6.5epss 0.01
Weak authentication in Windows Hello allows an authorized attacker to bypass a security feature over a network.
- risk 0.40cvss 6.1epss 0.01
Windows Hello Security Feature Bypass Vulnerability
- risk 0.37cvss 5.7epss 0.01
Windows Hello Security Feature Bypass Vulnerability
- risk 0.37cvss 5.7epss 0.01
Windows Hello Security Feature Bypass Vulnerability
- risk 0.36cvss 5.5epss 0.00
Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally.
- risk 0.33cvss 5.1epss 0.01
Automated recognition mechanism with inadequate detection or handling of adversarial input perturbations in Windows Hello allows an unauthorized attacker to perform spoofing locally.
- risk 0.29cvss 4.4epss 0.01
Uncontrolled search path element in Windows Hello allows an authorized attacker to bypass a security feature locally.
Page 1 of 2