CVE-2026-69725
7.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Summary
Double free in Windows Hello allows an authorized attacker to elevate privileges locally.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Microsoft | Windows 10 Version 21H2 | 10.0.19044.0 < 10.0.19044.7725 | affected |
| Microsoft | Windows 10 Version 22H2 | 10.0.19045.0 < 10.0.19045.7725 | affected |
| Microsoft | Windows 11 version 23H2 | 10.0.22631.0 < 10.0.22631.7582 | affected |
| Microsoft | Windows 11 Version 23H2 | 10.0.22631.0 < 10.0.22631.7582 | affected |
| Microsoft | Windows 11 Version 24H2 | 10.0.26100.0 < 10.0.26100.9445 | affected |
| Microsoft | Windows 11 Version 25H2 | 10.0.26200.0 < 10.0.26200.9445 | affected |
| Microsoft | Windows 11 version 26H1 | 10.0.28000.0 < 10.0.28000.2954 | affected |
Weaknesses
- CWE-415: CWE-415: Double Free
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.