Home
HIGH: 8.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N/E:U/RL:O/RC:C 10.0.14393.0 (custom) before 10.0.14393.9060
affected
10.0.14393.0 (custom) before 10.0.14393.9060
affected
10.0.17763.0 (custom) before 10.0.17763.8644
affected
10.0.17763.0 (custom) before 10.0.17763.8644
affected
10.0.20348.0 (custom) before 10.0.20348.5020
affected
10.0.25398.0 (custom) before 10.0.25398.2274
affected
10.0.26100.0 (custom) before 10.0.26100.32690
affected
10.0.26100.0 (custom) before 10.0.26100.32690
affected
Description
Improper input validation in Windows Hello allows an unauthorized attacker to bypass a security feature over a network.
Problem types
CWE-20: Improper Input Validation
Product status
References
msrc.microsoft.com/update-guide/vulnerability/CVE-2026-27928 (Windows Hello Security Feature Bypass Vulnerability)