Automated recognition mechanism with inadequate detection or handling of adversarial input perturbations in Windows Hello allows an unauthorized attacker to perform spoofing locally.
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-26644