CVE-2025-26644 | Microsoft Windows up to Server 2025 Hello automated recognition mechanism with inadequate detection or handling of adversarial input perturbations
A vulnerability, which was classified as problematic, has been found in Microsoft Windows up to Server 2025. Affected by this issue is some unknown functionality of the component Hello. The manipulation leads to automated recognition mechanism with inadequate detection or handling of adversarial input perturbations.
This vulnerability is handled as CVE-2025-26644. Local access is required to approach this attack. There is no exploit available.
It is recommended to apply a patch to fix this issue.