CVE-2026-81354
massHeap-Based Buffer Overflow in Microsoft Windows Hello Allows Local Privilege Escalation
Windows Hello, the biometric and PIN sign-in component built into Windows, contains a heap-based buffer overflow (CWE-122) that Microsoft rates high severity (CVSS 3.1: 8.2). The flaw is triggered locally by an attacker who already holds authorized high-privilege access to the system, when Windows Hello processes crafted input; the source data does not specify the exact code path. Successful exploitation allows the attacker to elevate privileges locally, and the CVSS scope-change (S:C) flag indicates the impact extends beyond the vulnerable component, with high confidentiality, integrity, and availability impact. Any Windows deployment containing the Windows Hello component is potentially affected, though exploitation requires prior local access with high privileges; specific affected build numbers were not provided in the source data. There is currently no known in-the-wild exploitation, no public proof-of-concept, no CISA KEV listing, and EPSS estimates only a 0.2% probability of exploitation within 30 days.
What to do: Apply Microsoft's security update for CVE-2026-81354 via Windows Update/WSUS as soon as it is released, prioritizing shared workstations, kiosks, and multi-user systems where several accounts hold local privileges. Until patched, restrict local administrative access to trusted users and monitor Microsoft's advisory for the exact affected build numbers. Given the 0.2% EPSS score, absence of KEV listing, and lack of public PoC, this can be handled in the regular patch cycle rather than as an emergency.
| Microsoft Windows Hello (Windows component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Hello allows an authorized attacker to elevate privileges locally.
- Vendors
- microsoft
- Products
- windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2019
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.