CVE-2026-69725
massDouble Free in Windows Hello Enables Local Privilege Escalation
A double free memory-safety flaw (CWE-415) exists in Windows Hello, Microsoft's biometric and PIN sign-in component, and is rated high severity (CVSS 7.8). An attacker who can already run code on a machine with a low-privileged account can trigger the double free, with no user interaction required. Successful exploitation yields local privilege elevation with high impact on confidentiality, integrity, and availability, meaning the attacker can gain elevated, likely administrative-level access to the affected system. Any Windows system using Windows Hello is potentially affected; the available data does not specify affected version ranges, so defenders should consult Microsoft's advisory for scope. The flaw is not yet known to be exploited: it is absent from CISA's KEV, EPSS estimates only a 0.3% chance of exploitation within 30 days, and no public proof-of-concept is known.
What to do: Install Microsoft's Windows security update addressing CVE-2026-69725 via Windows Update on all endpoints as soon as it is available, prioritizing shared or multi-user machines. Until patched, restrict local interactive logon to trusted accounts where feasible and verify remediation in Windows Update history. No public exploit or known workaround exists at this time.
| Microsoft Windows Hello (Windows sign-in component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Double free in Windows Hello allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-415
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.