ZeroHour

CVE-2026-69740

mass

Use-After-Free Local Privilege Escalation in Windows Hello

CVSS 3.1
8.8 high
EPSS
<1%p24
Published
()
Modified
AI analysis

CVE-2026-69740 is a use-after-free memory-corruption flaw (CWE-416) in Windows Hello, Microsoft's biometric and PIN sign-in component of Windows. Per the CVSS vector, an attacker who already holds low-privileged authorized access on a machine can trigger the bug locally without any user interaction. Successful exploitation crosses the security scope, allowing the attacker to elevate privileges with high impact on confidentiality, integrity, and availability. The disclosure data does not specify exact affected Windows builds; the flaw was addressed as part of Microsoft's September 2026 Patch Tuesday release. There is no known exploitation in the wild, no public proof of concept, the flaw is not in CISA KEV, and EPSS puts the 30-day exploitation probability at just 0.3% (24th percentile).

What to do: Deploy the Windows security updates released in Microsoft's September 2026 Patch Tuesday across all Windows 10/11 endpoints, prioritizing shared workstations, kiosks, and systems where untrusted users hold local accounts. Verify via your patch-management or vulnerability-scanning tooling that the applicable OS update containing this Windows Hello fix is installed. No interim mitigation or public PoC is documented, so prompt patching is the primary action.

Affected
Microsoft Windows Hello (biometric/PIN sign-in component of Windows 10/11)
Estimated exposure
masshundreds of millions of Windows endpoints (Windows Hello ships with Windows 10/11 on a >1-billion-device installed base) — Windows Hello is built into Windows 10 and Windows 11, whose combined installed base exceeds one billion devices, so the potential local attack surface spans at least hundreds of millions of endpoints, though exploitation requires local…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Hello allows an authorized attacker to elevate privileges locally.

Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news

Microsoft Patch Tuesday, September 2026 Security Update Review

Microsoft's September 2026 Patch Tuesday fixes 974 vulnerabilities, including 113 critical and two actively exploited Windows privilege escalation flaws.

Microsoft's September 2026 Patch Tuesday fixes 974 vulnerabilities, its largest release ever, including 113 critical and 860 important, covering Windows HTTP.sys, Hyper-V, Entra ID, Exchange Server, Office, DNS, and more. Two zero-days are confirmed exploited in the wild: CVE-2026-81963 (Windows Update Stack EoP) and CVE-2026-85880 (ALPC heap overflow), both letting authenticated attackers gain SYSTEM privileges. Notable criticals include an Entra ID authentication bypass (CVE-2026-62916) and multiple Windows DNS Server and Office remote code execution flaws.