Heap-based buffer overflow in Microsoft Windows - CVE-2026-69820
Published: September 8, 2026
Vulnerability details
The vulnerability allows a local privileged user to elevate privileges.
The vulnerability exists due to a heap-based buffer overflow in Windows Hello when exploited locally. A local privileged user can exploit the heap-based buffer overflow to elevate privileges.
Successful exploitation could provide Virtual Trust Level 1 (VTL1) privileges.