Junglewise Threat Intelligence

CVE-2026-20804: Microsoft Windows Hello incorrect privilege assignment

CVE-2026-20804 · Severity: high · CVSS 7.7 · Published 2026-01-13

Technologies: Microsoft Windows 11 24h2, Microsoft Windows Server 2022 23h2, Microsoft Windows 10 22h2, Microsoft Windows 11 23h2, Microsoft Windows 10 1809, Microsoft Windows Server 2025, Microsoft Windows Server 2022, Microsoft Windows 10, Microsoft Windows Server 2019, Microsoft Windows Server 2016, Microsoft Windows 10 21h2, Microsoft Windows 11 25h2, Microsoft Windows 11, Microsoft Windows 10 1607. Vendors: Microsoft.

Executive brief

A security vulnerability has been identified in Windows Hello, the biometric authentication system used to sign into Windows devices. An attacker with physical or local access to a device could potentially tamper with security settings or bypass certain protections due to incorrect permission settings. This could lead to unauthorized access to the device or the compromise of sensitive user data.

Technical details

A vulnerability classified as Incorrect Privilege Assignment (CWE-266) exists in Windows Hello. The flaw stems from improper access control settings that allow a local, unauthenticated attacker to perform unauthorized tampering with the component. While the attack requires local access, it does not require prior administrative privileges or user interaction. Successful exploitation could allow an attacker to compromise the integrity and confidentiality of the authentication system. Microsoft has released security updates to address this issue across affected versions of Windows 10, Windows 11, and Windows Server.

Affected products

  • Microsoft Windows 10 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 22H3, 23H2, 24H2, 25H2
  • Microsoft Windows Server 2016 All versions

Timeline

  • 2026-01-13: disclosed
  • 2026-01-13: patched

References

Related threats