Impact
An uncontrolled search path element flaw in Windows Hello permits an attacker who already has local authorization to bypass the Windows Hello security feature. The weakness, classified as CWE-427, allows the attacker to influence the search path used by Windows Hello, potentially causing the authentication process to execute unintended code or data. As a result, the attacker can avoid or subvert the biometric or PIN protection meant to restrict access to protected resources.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Windows Server editions 2016, 2019, 2022, and 2025 are all listed as affected. No other operating systems are mentioned in the CNA data. The impact is local and requires the attacker to already have administrative or privileged access to the affected machine.
Risk and Exploitability
The CVSS score of 4.4 indicates a moderate severity, and the EPSS score is not available, so the immediate likelihood of exploitation is unclear. This vulnerability is not listed in CISA’s KEV catalog, suggesting that widespread exploitation has not yet been observed. The likely attack vector is a local privileged attacker who can alter system paths or execute arbitrary code to influence the Windows Hello process. Exploitation requires the attacker to have sufficient privileges to modify the environment or deploy a malicious executable, meaning that denial of privilege escalation controls would be a prerequisite for successful use.
OpenCVE Enrichment