CVE-2026-69293
massLocal Privilege Escalation via Heap Buffer Overflow in Windows Biometric Service
CVE-2026-69293 is a heap-based buffer overflow (CWE-122, with underlying improper input validation per CWE-20) in the Windows Biometric Service, the Windows component that handles biometric logon such as Windows Hello. A locally authenticated attacker with low privileges can trigger the overflow by sending crafted input to the service, with no user interaction required. Successful exploitation corrupts heap memory in the service and allows the attacker to elevate privileges locally, gaining high confidentiality, integrity, and availability impact on the target system. Any Windows deployment running the Windows Biometric Service is affected, per Microsoft's advisory; specific affected build numbers are not listed in the available data. There is no evidence of active exploitation: the flaw is not in CISA's KEV, no public proof-of-concept is known, and EPSS estimates only a 0.2% chance of exploitation within 30 days.
What to do: Track Microsoft's security advisory for CVE-2026-69293 and apply the security update for affected Windows builds as soon as it is released, prioritizing shared or multi-user workstations where local users are less trusted. In the interim, verify which endpoints have biometric logon (Windows Hello) enabled and running the Biometric Service, and limit local accounts' ability to gain elevated access via standard least-privilege hardening. Re-check the advisory as Microsoft may publish specific affected builds and any mitigations.
| Microsoft Windows (Windows Biometric Service) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
- Weakness
- CWE-20, CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.