Weak authentication in Windows Hello allows an authorized attacker to bypass a security feature over a network.
The product uses an authentication mechanism to restrict access to specific users or identities, but the mechanism does not sufficiently prove that the claimed identity is correct.
Link | Tags |
---|---|
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-26635 | vendor advisory |