CVE-2026-69820 – Windows Hello Elevation of Privilege Vulnerability
CVSS 8.2
IMPORTANT
Critical - Same Day Deployment
“A Windows Hello memory flaw could turn existing local access into powerful VTL1 privileges, putting sensitive systems and data at greater risk.”
CVE-2026-69820 is a heap-based buffer overflow vulnerability in Windows Hello that allows an authorized local attacker to elevate privileges. Successful exploitation could give the attacker Virtual Trust Level 1 (VTL1) privileges. No exploitation or public disclosure is reported, and exploit code maturity is listed as unproven.
Key Details
- Attack Vector
- Local
- Attack Complexity
- Low
- Privileges Required
- High
- User Interaction
- None
- CWE Classification
- CWE-122
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.