ZeroHour

CVE-2026-69820

mass

Heap Buffer Overflow in Windows Hello Enables Local Privilege Escalation

CVSS 3.1
8.2 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-69820 is a heap-based buffer overflow (CWE-122) in Windows Hello, Microsoft's biometric authentication component for Windows. It is triggered locally by an already-authorized attacker, and the CVSS vector (PR:H, S:C) indicates high privileges are required to attempt the exploit and that the flaw crosses a security boundary when exploited. A successful attack yields elevation of privilege with high impact to confidentiality, integrity, and availability on the affected system. Any Windows deployment with the Windows Hello feature is in scope; the available data does not specify affected Windows builds or versions, so defenders should consult Microsoft's advisory. Exploitation status is currently quiet: no public proof-of-concept, not listed in CISA KEV, and EPSS estimates only a 0.3% probability of exploitation within 30 days.

What to do: Patch via Windows Update when Microsoft publishes the fix, and check the Microsoft advisory for the affected Windows builds to confirm coverage of your fleet. Because exploitation requires an already-privileged local actor, prioritize privileged-access workstations, servers, and VDI hosts for remediation, and review who holds local administrator rights. No public PoC or in-the-wild exploitation is known at this time, so routine patch-cycle remediation is reasonable for most endpoints.

Affected
Microsoft Windows Hello (feature of Microsoft Windows)
Estimated exposure
mass≈100M+ endpoints (Windows Hello ships with the modern Windows client installed base) — Windows Hello is bundled with Windows 10/11 client editions, whose installed base runs to hundreds of millions of devices per public OS market-share data, though practical exploit exposure is limited to attackers with existing local access…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Hello allows an authorized attacker to elevate privileges locally.

Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.