Executive brief
Windows Hello is Microsoft's biometric authentication system integrated into Windows that enables secure login via fingerprint or facial recognition. A use-after-free vulnerability allows an authorized user with local access to execute arbitrary code with elevated privileges, potentially compromising system security and gaining full administrative control.
Technical details
A use-after-free vulnerability exists in Windows Hello's memory management, where freed memory is accessed after deallocation. An authorized local attacker can trigger this flaw through specific interactions with the biometric authentication system to corrupt memory and execute arbitrary code with higher privileges. Exploitation requires local access and authentication as a user on the affected system. If successfully exploited, an attacker can escalate privileges to system or administrator level. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Windows Hello <UNKNOWN>
Timeline
- 2026-09-08: disclosed