Description
Heap-based buffer overflow in Windows Hello allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Patch immediately
AI Analysis

Impact

The vulnerability is a heap-based buffer overflow located within the Windows Hello authentication component. The flaw allows an attacker who already has local access to execute code with elevated privileges, potentially taking full control of the affected system. The weakness is listed as CWE-122, which represents a classic buffer overflow scenario that can overwrite critical memory structures and subvert control flow.

Affected Systems

Microsoft Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows 11 Version 26H1. No specific sub‑version or patch level is provided, but all listed operating system release streams are indicated as impacted.

Risk and Exploitability

The CVSS score of 8.2 classifies this as a high‑severity vulnerability. Because the attack vector is local (an authorized attacker), an exploiter must already have some level of system access, but can otherwise abnormally elevate to full administrative rights. The EPSS score is unavailable, making it unclear how frequently the flaw has already been seen in the wild, and the vulnerability is not currently listed in the CISA KEV catalog. The likely exploitation path would involve invoking a crafted Windows Hello session or message that triggers the buffer overflow, but these details are not fully documented in the description. Given the absence of an official fix or public workaround, users should treat this as a critical local privilege escalation risk.

Generated by OpenCVE AI on September 9, 2026 at 00:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Windows security updates from Microsoft to address the Windows Hello heap overflow.
  • Restrict or disable Windows Hello authentication for users who do not require it, limiting the number of accounts that could potentially exploit the flaw.
  • Monitor for indicators of exploitation, such as unexpected privilege escalation, anomalous authentication attempts, or abnormal process creation, and investigate promptly.

Generated by OpenCVE AI on September 9, 2026 at 00:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:x64:*

Thu, 10 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Vendors & Products Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1

Wed, 09 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Heap-based buffer overflow in Windows Hello allows an authorized attacker to elevate privileges locally.
Title Windows Hello Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Weaknesses CWE-122
CPEs cpe:2.3:o:microsoft:windows_10_21H2:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_22H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_23H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_23H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 10 21h2 Windows 10 21h2 Windows 10 22h2 Windows 10 22h2 Windows 11 23h2 Windows 11 23h2 Windows 11 24h2 Windows 11 24h2 Windows 11 25h2 Windows 11 25h2 Windows 11 26h1 Windows 11 26h1
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:36:42.836Z

Reserved: 2026-08-03T22:50:31.851Z

Link: CVE-2026-69820

cve-icon Vulnrichment

Updated: 2026-09-09T09:55:29.882Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:19:53.747

Modified: 2026-09-16T21:25:01.447

Link: CVE-2026-69820

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:55:16Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow