Executive brief
Windows Hello is Microsoft's biometric authentication system used to unlock devices and authenticate users. A heap-based buffer overflow in this component could allow an authorized attacker with local access to execute code with elevated privileges, potentially compromising device security and user data.
Technical details
A heap-based buffer overflow exists in Windows Hello, triggered during processing of biometric authentication data. The vulnerability allows an authorized local attacker to overflow a heap buffer and potentially execute arbitrary code with elevated privileges. Attack preconditions include local access to the system and prior authentication. Exploitation can lead to privilege escalation from the authenticated context. A patch is expected to be available through Microsoft's standard security update process.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed