Microsoft Windows Hello Security Feature Bypass Vulnerability
Vulnerability
A vulnerability has been identified in Windows Hello that allows an unauthorized attacker to locally bypass a security feature. This issue arises from the cleartext transmission of sensitive information, which can be exploited to circumvent the facial and fingerprint recognition security measures of Windows Hello.
Impact
Exploitation of this vulnerability could lead to a bypass of the Windows Hello facial and fingerprint recognition security features.
Remediation
Users can download the security update for this vulnerability through the Microsoft Update Catalog. Specific update details can be found in the Microsoft Knowledge Base articles KB5066791 for Windows 10 and KB5066793 for Windows 11. For Windows Server 2025, the relevant update is also available via the Microsoft Update Catalog.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
