Impact
Windows Hello stores certain confidential information in cleartext, which an authorized local user can exploit to tamper with or modify Hello credentials or related settings. This flaw falls under the weakness identified as CWE-312: Cleartext Storage of Sensitive Information. The vulnerability does not provide remote code execution or denial‑of‑service, but it allows an attacker with local privilege to change or compromise Hello authentication data.
Affected Systems
Microsoft Windows 10 releases starting from version 1607 to 22H2, Windows 11 releases from 23H2 to 26H1, and Windows Server 2016, 2019, 2022, and 2025 (both full and core installations).
Risk and Exploitability
The CVSS score of 5.5 indicates moderate risk. With an EPSS score of less than 1%, the likelihood of exploitation is low. The vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation. Attackers would need authorized local access, so the vector is likely a local authenticated user or a compromised account with sufficient privileges.
OpenCVE Enrichment