ZeroHour

CVE-2026-69293

mass

Local Privilege Escalation via Heap Buffer Overflow in Windows Biometric Service

CVSS 3.1
7.8 high
EPSS
<1%p16
Published
()
Modified
AI analysis

CVE-2026-69293 is a heap-based buffer overflow (CWE-122, with underlying improper input validation per CWE-20) in the Windows Biometric Service, the Windows component that handles biometric logon such as Windows Hello. A locally authenticated attacker with low privileges can trigger the overflow by sending crafted input to the service, with no user interaction required. Successful exploitation corrupts heap memory in the service and allows the attacker to elevate privileges locally, gaining high confidentiality, integrity, and availability impact on the target system. Any Windows deployment running the Windows Biometric Service is affected, per Microsoft's advisory; specific affected build numbers are not listed in the available data. There is no evidence of active exploitation: the flaw is not in CISA's KEV, no public proof-of-concept is known, and EPSS estimates only a 0.2% chance of exploitation within 30 days.

What to do: Track Microsoft's security advisory for CVE-2026-69293 and apply the security update for affected Windows builds as soon as it is released, prioritizing shared or multi-user workstations where local users are less trusted. In the interim, verify which endpoints have biometric logon (Windows Hello) enabled and running the Biometric Service, and limit local accounts' ability to gain elevated access via standard least-privilege hardening. Re-check the advisory as Microsoft may publish specific affected builds and any mitigations.

Affected
Microsoft Windows (Windows Biometric Service)
Estimated exposure
mass≈ hundreds of millions of Windows installations (component ships by default on Windows 10/11) — The Windows Biometric Service is present by default on Windows 10/11, whose installed base exceeds one billion devices, so the potentially affected population is on the order of hundreds of millions of systems, though exploitation requires…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-20, CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.