Automated recognition mechanism with inadequate detection or handling of adversarial input perturbations in Windows Hello allows an unauthorized attacker to perform spoofing locally.
2025-04-08T18:15:48.347
2025-07-10T15:56:24.903
Analyzed
CVSSv3.1: 5.1 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | microsoft | windows_10_1809 | < 10.0.17763.7136 | Yes |
Operating System | microsoft | windows_10_1809 | < 10.0.17763.7136 | Yes |
Operating System | microsoft | windows_10_21h2 | < 10.0.19044.5737 | Yes |
Operating System | microsoft | windows_10_22h2 | < 10.0.19045.5737 | Yes |
Operating System | microsoft | windows_11_22h2 | < 10.0.22621.5189 | Yes |
Operating System | microsoft | windows_11_23h2 | < 10.0.22631.5189 | Yes |
Operating System | microsoft | windows_11_24h2 | < 10.0.26100.3775 | Yes |
Operating System | microsoft | windows_server_2019 | < 10.0.17763.7136 | Yes |
Operating System | microsoft | windows_server_2025 | < 10.0.26100.3775 | Yes |