Executive brief
Windows Hello is Microsoft's biometric authentication system used to secure user access to Windows devices. An authorized attacker could manipulate the search path used by Windows Hello to bypass security protections, potentially allowing them to gain elevated privileges or circumvent authentication controls on a local system.
Technical details
This vulnerability is a path traversal or uncontrolled search path element flaw in Windows Hello that allows an authorized local attacker to bypass a security feature. The vulnerability requires local access and authorization to exploit; it does not allow remote exploitation. By manipulating the search path, an attacker can redirect Windows Hello to load unintended code or skip security checks. Microsoft has released security updates to address this issue by validating and restricting the search path used by the Windows Hello service.
Affected products
- Microsoft Windows Hello
Timeline
- 2026-09-08: disclosed