Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-17767 | Exposure of sensitive information to an unauthorized actor in Windows Hello allows an authorized attacker to disclose information locally. |
Fri, 13 Feb 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microsoft windows 11 22h2
Microsoft windows 11 23h2 Microsoft windows 11 24h2 |
|
| CPEs | cpe:2.3:o:microsoft:windows_11_22H2:*:*:*:*:*:*:arm64:* cpe:2.3:o:microsoft:windows_11_23H2:*:*:*:*:*:*:arm64:* cpe:2.3:o:microsoft:windows_11_23H2:*:*:*:*:*:*:x64:* cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:* |
|
| Vendors & Products |
Microsoft windows 11 22h2
Microsoft windows 11 23h2 Microsoft windows 11 24h2 |
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 09 Jul 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microsoft
Microsoft windows 11 22h2 Microsoft windows 11 23h2 Microsoft windows 11 24h2 Microsoft windows Server 2025 |
|
| CPEs | cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Microsoft
Microsoft windows 11 22h2 Microsoft windows 11 23h2 Microsoft windows 11 24h2 Microsoft windows Server 2025 |
Tue, 10 Jun 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 10 Jun 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Exposure of sensitive information to an unauthorized actor in Windows Hello allows an authorized attacker to disclose information locally. | |
| Title | Windows Virtualization-Based Security (VBS) Information Disclosure Vulnerability | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2026-02-20T16:00:54.022Z
Reserved: 2025-05-14T14:13:13.465Z
Link: CVE-2025-47969
Updated: 2025-06-10T18:22:20.857Z
Status : Analyzed
Published: 2025-06-10T17:24:15.183
Modified: 2025-07-09T16:49:50.947
Link: CVE-2025-47969
No data.
OpenCVE Enrichment
No data.
EUVD