CVE-2026-69298
massInteger Overflow Privilege Escalation in Microsoft Windows Biometric Service
CVE-2026-69298 is an integer overflow or wraparound flaw (CWE-190) in the Windows Biometric Service, the Windows component that handles fingerprint, facial recognition, and other biometric authentication requests. A local attacker who is already authorized on the system with standard (low) user privileges can trigger the overflow through the service without any user interaction, since the attack vector is local and the complexity is low. Successful exploitation allows the attacker to elevate privileges on the local machine, with high impact on confidentiality, integrity, and availability, though the flaw does not lead to remote code execution or compromise of other systems. Any Windows deployment running the Biometric Service is potentially affected, though Microsoft has not specified the exact affected version ranges in the available data. There is currently no known exploitation: the flaw is not in CISA's KEV catalog, no public proof-of-concept is known, and EPSS estimates only a 0.3% probability of exploitation within 30 days.
What to do: Install the Windows security update for CVE-2026-69298 via Windows Update as soon as Microsoft releases it, and check Microsoft's advisory for the specific affected builds since version ranges are not yet enumerated in this data. Until patched, limit exposure by restricting which standard users can run code on shared Windows hosts and reviewing local account assignments. Because exploitation requires local access with low privileges, internet-facing exposure is not the primary concern; prioritize endpoints where multiple low-privilege users or untrusted local processes run, such as shared workstations and VDI.
| Microsoft Windows Biometric Service (Windows) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
- Weakness
- CWE-190
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.