ZeroHour

CVE-2026-69725

mass

Double Free in Windows Hello Enables Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p24
Published
()
Modified
AI analysis

A double free memory-safety flaw (CWE-415) exists in Windows Hello, Microsoft's biometric and PIN sign-in component, and is rated high severity (CVSS 7.8). An attacker who can already run code on a machine with a low-privileged account can trigger the double free, with no user interaction required. Successful exploitation yields local privilege elevation with high impact on confidentiality, integrity, and availability, meaning the attacker can gain elevated, likely administrative-level access to the affected system. Any Windows system using Windows Hello is potentially affected; the available data does not specify affected version ranges, so defenders should consult Microsoft's advisory for scope. The flaw is not yet known to be exploited: it is absent from CISA's KEV, EPSS estimates only a 0.3% chance of exploitation within 30 days, and no public proof-of-concept is known.

What to do: Install Microsoft's Windows security update addressing CVE-2026-69725 via Windows Update on all endpoints as soon as it is available, prioritizing shared or multi-user machines. Until patched, restrict local interactive logon to trusted accounts where feasible and verify remediation in Windows Update history. No public exploit or known workaround exists at this time.

Affected
Microsoft Windows Hello (Windows sign-in component)
Estimated exposure
mass≈hundreds of millions of Windows 10/11 devices (Windows Hello ships built into Windows) — Windows Hello is a default component of Windows 10/11, which power most of Microsoft's roughly one-billion-plus active Windows devices, and PIN/biometric sign-in is enrolled by default or commonly on modern PCs, so exposure is at the mass…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Double free in Windows Hello allows an authorized attacker to elevate privileges locally.

Weakness
CWE-415
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.