CVE-2025-47969: Microsoft Windows 11 22h2
Medium severity, CVSS 4.4. EPSS: 0.6% chance of exploitation in the next 30 days.
Exposure of sensitive information to an unauthorized actor in Windows Hello allows an authorized attacker to disclose information locally.
Affected products
- Microsoft Windows 11 22h2: before 10.0.22621.5335 (fixed in 10.0.22621.5335)
- Microsoft Windows 11 23h2: before 10.0.22621.5335 (fixed in 10.0.22621.5335)
- Microsoft Windows 11 24h2: before 10.0.26100.3981 (fixed in 10.0.26100.3981)
- Microsoft Windows Server 2025: before 10.0.26100.3981 (fixed in 10.0.26100.3981)
Published 2025-06-10. Last modified 2026-06-17.