#VU117278 Cleartext transmission of sensitive information in Windows Server and Windows - CVE-2025-53139
Published: October 15, 2025
Windows Server
Windows
Microsoft
Description
The vulnerability allows a local attacker to gain access to sensitive information.
The vulnerability exists due to software uses insecure communication channel to transmit sensitive information in Windows Hello. A local attacker can gain access to sensitive data and bypass the Windows Hello Facial and Fingerprint Recognition security feature.