CVE-2025-47969Sensitive Information Exposure in Microsoft Windows 11 Version 22h2

Severity
4.4MEDIUMNVD
EPSS
1.0%
top 22.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 10

Description

Exposure of sensitive information to an unauthorized actor in Windows Hello allows an authorized attacker to disclose information locally.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:NExploitability: 0.8 | Impact: 3.6

Affected Packages9 packages

NVDmicrosoft/windows< 10.0.26100.3981
NVDmicrosoft/windows_11_22h2< 10.0.22621.5335
NVDmicrosoft/windows_11_23h2< 10.0.22621.5335
NVDmicrosoft/windows_11_24h2< 10.0.26100.3981
CVEListV5microsoft/windows_server_202510.0.26100.010.0.26100.4061

🔴Vulnerability Details

2
CVEList
Windows Virtualization-Based Security (VBS) Information Disclosure Vulnerability2025-06-10
GHSA
GHSA-36wp-r9w6-8qw8: Exposure of sensitive information to an unauthorized actor in Windows Hello allows an authorized attacker to disclose information locally2025-06-10

📋Vendor Advisories

1
Microsoft
Windows Virtualization-Based Security (VBS) Information Disclosure Vulnerability2025-06-10

🕵️Threat Intelligence

1
Bleepingcomputer
Microsoft June 2025 Patch Tuesday fixes exploited zero-day, 66 flaws2025-06-10
CVE-2025-47969 — Sensitive Information Exposure | cvebase