Executive brief
Windows Hello is Microsoft's biometric authentication system used to unlock Windows devices. A heap buffer overflow in this component allows an authorized local attacker to escalate their privileges on the system, potentially gaining administrative access and full control of the device.
Technical details
A heap-based buffer overflow exists in Windows Hello's memory handling. The vulnerability requires the attacker to already have local access and be able to execute code on the system. By crafting a malicious input or triggering specific Windows Hello operations, an attacker can overflow a heap buffer and overwrite adjacent memory structures. This allows arbitrary code execution at a higher privilege level, enabling local privilege escalation to administrator or SYSTEM level.
Affected products
- Microsoft Windows Hello unknown
Timeline
- 2026-09-08: disclosed