Home
MEDIUM: 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C 10.0.22621.0 (custom) before 10.0.22621.5335
affected
10.0.22631.0 (custom) before 10.0.22621.5335
affected
10.0.22631.0 (custom) before 10.0.22621.5335
affected
10.0.26100.0 (custom) before 10.0.26100.4061
affected
10.0.26100.0 (custom) before 10.0.26100.4061
affected
10.0.26100.0 (custom) before 10.0.26100.4061
affected
Description
Exposure of sensitive information to an unauthorized actor in Windows Hello allows an authorized attacker to disclose information locally.
Problem types
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
Product status
References
msrc.microsoft.com/update-guide/vulnerability/CVE-2025-47969 (Windows Virtualization-Based Security (VBS) Information Disclosure Vulnerability)