CVE-2021-42288

Severity
6.1MEDIUM
EPSS
0.6%
top 31.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 10
Latest updateMay 24

Description

Windows Hello Security Feature Bypass Vulnerability

CVSS vector

CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 0.5 | Impact: 5.2

Affected Packages11 packages

CVEListV5microsoft/windows_server_201910.0.010.0.17763.2300
CVEListV5microsoft/windows_10_version_180910.0.010.0.17763.2300
CVEListV5microsoft/windows_10_version_190910.0.010.0.18363.1916
CVEListV5microsoft/windows_10_version_200410.0.010.0.19041.1348
CVEListV5microsoft/windows_10_version_20h210.0.010.0.19042.1348

Patches

🔴Vulnerability Details

2
GHSA
GHSA-6ww5-4467-wvxf: Windows Hello Security Feature Bypass Vulnerability2022-05-24
CVEList
Windows Hello Security Feature Bypass Vulnerability2021-11-10

📋Vendor Advisories

1
Microsoft
Windows Hello Security Feature Bypass Vulnerability2021-11-09
CVE-2021-42288 (MEDIUM CVSS 6.1) | Windows Hello Security Feature Bypa | cvebase.io