Junglewise Threat Intelligence

CVE-2026-69784: Microsoft Windows Hello use-after-free privilege escalation

CVE-2026-69784 · Severity: high · CVSS 8.8 · Published 2026-09-08

Executive brief

Windows Hello is Microsoft's biometric and PIN authentication system built into Windows. A use-after-free vulnerability allows an authorized local user to elevate their privileges on a system, potentially gaining administrative access and full control over the machine and its data.

Technical details

This vulnerability is a use-after-free flaw in the Windows Hello component that can be exploited by an authenticated local attacker to achieve privilege escalation. The vulnerability requires the attacker to already have local access to the system. Successful exploitation allows an attacker to execute code with elevated privileges (potentially SYSTEM level), bypassing standard privilege boundaries. A patch from Microsoft is expected to address this issue.

Affected products

  • Microsoft Windows Windows 10, Windows 11 (exact versions requiring verification)

Timeline

  • 2026-09-08: disclosed

References

Related threats