LiveActive security incident?Get immediate response
CVE Record

CVE-2025-26644: Windows Hello Spoofing Vulnerability

Automated recognition mechanism with inadequate detection or handling of adversarial input perturbations in Windows Hello allows an unauthorized attacker to perform spoofing locally.

MediumCVSS 5.1Not KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

This Windows Hello flaw could let an unauthorized person with local access impersonate a legitimate user. Successful exploitation could compromise account or system integrity, but the attack is rated high complexity and is not remotely exploitable. The supplied evidence does not indicate active exploitation.

Executive priority

Treat this as a normal-priority security update, with faster handling for shared, portable, or otherwise locally accessible Windows Hello systems. The moderate score and high attack complexity reduce urgency, but successful spoofing could undermine trusted authentication and permit unauthorized actions.

Technical view

Windows Hello inadequately detects or handles adversarial input perturbations in its automated recognition mechanism. A local, unauthenticated attacker could exploit this to spoof authentication, causing high integrity impact without identified confidentiality or availability impact. The supplied CVSS 3.1 score is 5.1.

Likely exposure

Exposure includes the listed Windows 10, Windows 11, Windows Server 2019, and Windows Server 2025 versions, particularly systems using Windows Hello. Actual exposure depends on installed security updates and whether the vulnerable authentication functionality is enabled or used.

Exploitation context

The attack vector is local, requires high complexity, and requires neither prior privileges nor user interaction according to the supplied CVSS vector. The CVE is not listed in KEV, and the source bundle provides no evidence of active exploitation or a public exploit.

Researcher notes

CWE-1039 characterizes inadequate handling of adversarial perturbations in automated recognition. The supplied evidence establishes local spoofing and high integrity impact but does not describe the required perturbation, affected Windows Hello modality, practical reliability, or attack prerequisites beyond the CVSS metrics. Consult the Microsoft advisory for release-specific update details.

Mitigation direction

  • Review Microsoft's CVE advisory and identify the applicable security update for each affected Windows release.
  • Deploy the applicable Microsoft security updates through the organization's normal endpoint and server patching process.
  • Prioritize locally accessible systems that use Windows Hello for authentication.
  • Check Microsoft guidance for any release-specific mitigations where immediate updating is unavailable.

Validation and detection

  • Inventory systems running the affected Windows releases and builds listed in the advisory.
  • Identify which inventoried systems have Windows Hello enabled or used for authentication.
  • Verify the applicable Microsoft security update is installed using trusted patch-management records.
  • Recheck update compliance after deployment and investigate systems that remain unpatched.
Prepared
Confidence
high
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · low confidence lookup

CWE-1039: Exact CWE lookup

Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2025-26644 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Medium
CVSS
5.1 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
3Timeline events
1ADP providers
2Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: partial

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
5.1CVSS 3.1MediumCVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C1.43.6microsoft

Vulnerability scoring details

Base CVSS 3.1 score

5.1Medium
CVSS 3.1 vector shape for CVE-2025-26644Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
other:ssvc

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
MicrosoftWindows 10 Version 180910.0.17763.0Listed
MicrosoftWindows 10 Version 21H210.0.19044.0Listed
MicrosoftWindows 10 Version 22H210.0.19045.0Listed
MicrosoftWindows 11 version 22H210.0.22621.0Listed
MicrosoftWindows 11 version 22H310.0.22631.0Listed
MicrosoftWindows 11 Version 23H210.0.22631.0Listed
MicrosoftWindows 11 Version 24H210.0.26100.0Listed
MicrosoftWindows Server 201910.0.17763.0Listed
MicrosoftWindows Server 2019 (Server Core installation)10.0.17763.0Listed
MicrosoftWindows Server 202510.0.26100.0Listed
MicrosoftWindows Server 2025 (Server Core installation)10.0.26100.0Listed
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-1039 · source CWE mapping

Inadequate Detection or Handling of Adversarial Input Perturbations in Automated Recognition Mechanism

Inadequate Detection or Handling of Adversarial Input Perturbations in Automated Recognition Mechanism represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.