Junglewise Threat Intelligence

CVE-2026-69740: Microsoft Windows Hello use-after-free privilege escalation

CVE-2026-69740 · Severity: high · CVSS 8.8 · Published 2026-09-08

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

Windows Hello is Microsoft's biometric authentication system built into Windows. A use-after-free vulnerability in this component allows an authenticated local attacker to escalate their privileges on the system, potentially gaining administrative access and full control over the device.

Technical details

A use-after-free vulnerability exists in the Windows Hello authentication component, where memory is accessed after being freed. This vulnerability requires the attacker to have local access and valid credentials on the system. The flaw allows a local authenticated attacker to execute arbitrary code with elevated privileges, leading to local privilege escalation. No public exploit has been reported in the wild at this time. A patch is expected to be available through Microsoft's security update process.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats