Impact
A double‑free bug in Windows Hello can be triggered by an authorized local user, allowing them to gain privileges higher than those normally granted to the process that recorded the double free. The flaw falls under CWE‑415 and can be used to compromise account isolation, potentially giving an attacker system‑wide control. The vulnerability does not provide remote code execution; it requires the attacker to have existing local access and sufficient privileges to exploit the memory management flaw.
Affected Systems
Microsoft Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows 11 Version 26H1. These are the Windows releases identified by the CNA for this double‑free bug.
Risk and Exploitability
The CVSS score of 7.8 categorizes this issue as a high‑severity vulnerability. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers would need local, authorized access to trigger the bug; no remote exploitation vector is known. Therefore, the risk is elevated for machines that rely on Windows Hello for authentication, especially if the feature is enabled for privileged accounts.
OpenCVE Enrichment