ZeroHour

CVE-2026-69864

mass

Use-after-free local privilege escalation in Microsoft Windows Hello

CVSS 3.1
7.8 high
EPSS
<1%p15
Published
()
Modified
AI analysis

CVE-2026-69864 is a use-after-free memory flaw (CWE-416) in Windows Hello, the Windows biometric/PIN sign-in component, assigned by Microsoft. An authorized attacker who already has a low-privileged local foothold can trigger the premature memory free and reuse condition to elevate privileges, with high attack complexity but no user interaction required. Successful exploitation yields high-impact gains to confidentiality, integrity, and availability beyond the vulnerable component (scope change), effectively meaning code execution at higher privilege on the local machine. Every Windows deployment with the Windows Hello component is potentially in scope; the data does not specify which Windows releases are affected, so consult Microsoft's advisory for the exact affected ranges. Exploitation status is currently quiet: EPSS is just 0.2% (15th percentile), the flaw is not in CISA's KEV catalog, and no public proof-of-concept is known.

What to do: Apply the Windows security update that addresses CVE-2026-69864 via Windows Update as soon as your organization's patch cycle allows, and check Microsoft's advisory for the exact affected Windows releases. Prioritize shared, multi-user, or kiosk-style endpoints where local accounts are commonly created, and verify Windows Hello enrollment/usage on those hosts. Watch for a public PoC or KEV listing, which would raise patching urgency.

Affected
Microsoft Windows Hello (Windows operating system sign-in component)
Estimated exposure
masshundreds of millions of Windows devices (Windows Hello ships with Windows 10/11), though exploitation requires local access — Windows Hello is a built-in sign-in component bundled with modern Windows releases rather than a separately installed add-on, so potential exposure is on the order of the Windows installed base, limited to hosts where an attacker already…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Hello allows an authorized attacker to elevate privileges locally.

Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.