Executive brief
A vulnerability in Windows Hello, the biometric authentication system for Windows, could allow an unauthorized person with physical or local access to a device to tamper with security settings. This could potentially lead to the exposure of sensitive information or the bypass of intended security controls. Organizations should ensure that the latest Windows security updates are applied to all workstations and servers to mitigate this risk.
Technical details
An incorrect privilege assignment vulnerability (CWE-266) exists in Windows Hello. A local attacker can exploit this flaw to perform unauthorized tampering with the component. The vulnerability does not require elevated privileges or user interaction, though it does require local access to the target system. Successful exploitation could result in high impacts to confidentiality and integrity. Microsoft has released security updates to address this issue across affected versions of Windows 10, Windows 11, and Windows Server 2016.
Affected products
- Microsoft Windows 10 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 22H3, 23H2, 24H2, 25H2
- Microsoft Windows Server 2016 All versions
Timeline
- 2026-01-13: disclosed
- 2026-01-13: advisory