ZeroHour

CVE-2026-81354

mass

Heap-Based Buffer Overflow in Microsoft Windows Hello Allows Local Privilege Escalation

CVSS 3.1
8.2 high
EPSS
<1%p15
Published
()
Modified
AI analysis

Windows Hello, the biometric and PIN sign-in component built into Windows, contains a heap-based buffer overflow (CWE-122) that Microsoft rates high severity (CVSS 3.1: 8.2). The flaw is triggered locally by an attacker who already holds authorized high-privilege access to the system, when Windows Hello processes crafted input; the source data does not specify the exact code path. Successful exploitation allows the attacker to elevate privileges locally, and the CVSS scope-change (S:C) flag indicates the impact extends beyond the vulnerable component, with high confidentiality, integrity, and availability impact. Any Windows deployment containing the Windows Hello component is potentially affected, though exploitation requires prior local access with high privileges; specific affected build numbers were not provided in the source data. There is currently no known in-the-wild exploitation, no public proof-of-concept, no CISA KEV listing, and EPSS estimates only a 0.2% probability of exploitation within 30 days.

What to do: Apply Microsoft's security update for CVE-2026-81354 via Windows Update/WSUS as soon as it is released, prioritizing shared workstations, kiosks, and multi-user systems where several accounts hold local privileges. Until patched, restrict local administrative access to trusted users and monitor Microsoft's advisory for the exact affected build numbers. Given the 0.2% EPSS score, absence of KEV listing, and lack of public PoC, this can be handled in the regular patch cycle rather than as an emergency.

Affected
Microsoft Windows Hello (Windows component)
Estimated exposure
massRoughly 1 billion+ Windows devices include the Windows Hello component, with likely hundreds of millions actively using Hello sign-in — Windows Hello ships by default in Windows 10/11, whose combined active install base exceeds one billion devices per Microsoft's published figures, though actual risk is narrower because exploitation requires an attacker with existing local…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Hello allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2019
Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.