Microsoft Windows Hello是美国微软(Microsoft)公司的一种基于生物识别的登录方式,可以使用您的面部、指纹或 PIN 进行登录。 Microsoft Windows Hello存在输入验证错误漏洞。攻击者利用该漏洞可以绕过某些功能。以下产品和版本受到影响:Windows 10 Version 22H2 for 32-bit Systems,Windows 11 Version 25H2 for ARM systems,Windows 11 Version 25H2 for x6
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Microsoft | Windows 10 Version 21H2 | 10.0.19044.0< 10.0.19044.7184 |
affected |
| Microsoft | Windows 10 Version 22H2 | 10.0.19045.0< 10.0.19045.7184 |
affected |
| Microsoft | Windows 11 version 22H3 | 10.0.22631.0< 10.0.22631.6936 |
affected |
| Microsoft | Windows 11 Version 23H2 | 10.0.22631.0< 10.0.22631.6936 |
affected |
| Microsoft | Windows 11 Version 24H2 | 10.0.26100.0< 10.0.26100.8246 |
affected |
| Microsoft | Windows 11 Version 25H2 | 10.0.26200.0< 10.0.26200.8246 |
affected |
| Microsoft | Windows 11 version 26H1 | 10.0.28000.0< 10.0.28000.1836 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Microsoft | Windows 10 Version 21H2 | 10.0.19044.0 ~ 10.0.19044.7184 | - |
|
| Microsoft | Windows 10 Version 22H2 | 10.0.19045.0 ~ 10.0.19045.7184 | - |
|
| Microsoft | Windows 11 version 22H3 | 10.0.22631.0 ~ 10.0.22631.6936 | - |
|
| Microsoft | Windows 11 Version 23H2 | 10.0.22631.0 ~ 10.0.22631.6936 | - |
|
| Microsoft | Windows 11 Version 24H2 | 10.0.26100.0 ~ 10.0.26100.8246 | - |
|
| Microsoft | Windows 11 Version 25H2 | 10.0.26200.0 ~ 10.0.26200.8246 | - |
|
| Microsoft | Windows 11 version 26H1 | 10.0.28000.0 ~ 10.0.28000.1836 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-33824 | 9.8 CRITICAL | Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability |
| CVE-2026-26149 | 9.0 CRITICAL | Microsoft Power Apps Desktop Client Spoofing Vulnerability |
| CVE-2026-32225 | 8.8 HIGH | Windows Shell Security Feature Bypass Vulnerability |
| CVE-2026-26167 | 8.8 HIGH | Windows Push Notifications Elevation of Privilege Vulnerability |
| CVE-2026-32157 | 8.8 HIGH | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-33120 | 8.8 HIGH | Microsoft SQL Server Remote Code Execution Vulnerability |
| CVE-2026-32171 | 8.8 HIGH | Azure Logic Apps Elevation of Privilege Vulnerability |
| CVE-2026-26178 | 8.8 HIGH | Windows Advanced Rasterization Platform Elevation of Privilege Vulnerability |
| CVE-2026-27928 | 8.7 HIGH | Windows Hello Security Feature Bypass Vulnerability |
| CVE-2026-32221 | 8.4 HIGH | Windows Graphics Component Remote Code Execution Vulnerability |
| CVE-2026-32091 | 8.4 HIGH | Microsoft Brokering File System Elevation of Privilege Vulnerability |
| CVE-2026-32162 | 8.4 HIGH | Windows COM Elevation of Privilege Vulnerability |
| CVE-2026-33115 | 8.4 HIGH | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2026-33114 | 8.4 HIGH | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2026-32190 | 8.4 HIGH | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-33827 | 8.1 HIGH | Windows TCP/IP Remote Code Execution Vulnerability |
| CVE-2026-27912 | 8.0 HIGH | Windows Kerberos Elevation of Privilege Vulnerability |
| CVE-2026-33826 | 8.0 HIGH | Windows Active Directory Remote Code Execution Vulnerability |
| CVE-2026-33098 | 7.8 HIGH | Windows Container Isolation FS Filter Driver Elevation of Privilege Vulnerability |
| CVE-2026-23657 | 7.8 HIGH | Microsoft Word Remote Code Execution Vulnerability |
Showing top 20 of 163 CVEs. View all on vendor page → →
No comments yet