Security
Headlines
HeadlinesLatestCVEs

Latest News

CVE-2025-26635: Windows Hello Security Feature Bypass Vulnerability

**What kind of security feature could be bypassed by successfully exploiting this vulnerability?** An attacker who successfully exploited this vulnerability could bypass the Windows Hello security feature. **Where can I find more information about Windows Hello?** Please see Windows Hello | Microsoft Learn for more details.

Microsoft Security Response Center
#vulnerability#windows#microsoft#Windows Hello#Security Vulnerability
CVE-2025-27727: Windows Installer Elevation of Privilege Vulnerability

Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to elevate privileges locally.

CVE-2025-27492: Windows Secure Channel Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Secure Channel allows an authorized attacker to elevate privileges locally.