CVE-2026-69799
massRace Condition in Microsoft Windows Hello Enables Local Privilege Escalation
CVE-2026-69799 is a race condition (CWE-362, concurrent execution using a shared resource with improper synchronization) in Microsoft's Windows Hello authentication component. It is triggered when concurrent operations touch a shared resource without proper synchronization during Windows Hello processing, and exploiting it requires an attacker who already has local, low-privileged access to the device (high attack complexity because it depends on timing). Successful exploitation lets the authorized local user elevate privileges across a security-scope boundary, with high impact on confidentiality, integrity, and availability. Any Windows device with Windows Hello available or enrolled is potentially affected; the affected version ranges are not specified in the available data. Exploitation status: no public proof-of-concept, not listed in CISA KEV, and a low EPSS score (0.2% probability of exploitation in the next 30 days, 8th percentile), so no known exploitation is underway.
What to do: Apply Microsoft's security update for this Windows Hello privilege-elevation issue via Windows Update (or your patch management system) as soon as it is released. Prioritize shared workstations, kiosks, and multi-user endpoints where local low-privileged accounts are common, and confirm Windows Hello (PIN/biometric) enrollment on managed devices to gauge relevance. Monitor Microsoft advisories and CISA KEV, since no public PoC exists today and exploitation status could change.
| Microsoft Windows (Windows Hello component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hello allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-362
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.