CVE-2026-69820 – Windows Hello Elevation of Privilege Vulnerability

CVSS 8.2 IMPORTANT Critical - Same Day Deployment

“A Windows Hello memory flaw could turn existing local access into powerful VTL1 privileges, putting sensitive systems and data at greater risk.”

CVE-2026-69820 is a heap-based buffer overflow vulnerability in Windows Hello that allows an authorized local attacker to elevate privileges. Successful exploitation could give the attacker Virtual Trust Level 1 (VTL1) privileges. No exploitation or public disclosure is reported, and exploit code maturity is listed as unproven.

Key Details

Attack Vector
Local
Attack Complexity
Low
Privileges Required
High
User Interaction
None
CWE Classification
CWE-122
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.