ZeroHour

CVE-2026-69323

mass

Heap Buffer Overflow in Windows Biometric Service Enables Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-69323 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, a built-in Windows component. A low-privileged, already-authorized local attacker can trigger the flaw without user interaction by interacting with the service in a way that overflows a heap buffer. Successful exploitation lets the attacker elevate privileges locally, gaining high integrity-level access with potential for full confidentiality, integrity, and availability impact on the host. Any Windows system running the Biometric Service is affected, with shared or multi-user Windows hosts and kiosks the most meaningful attack surface since exploitation requires local access. No public proof-of-concept, KEV listing, or known in-the-wild exploitation is currently reported, and EPSS assigns a low 0.3% probability of exploitation within 30 days.

What to do: Install Microsoft's security update addressing CVE-2026-69323 as soon as it is available, prioritizing shared Windows hosts, kiosks, and remote-workstation servers where untrusted users hold local logon rights. As an interim check, determine whether the Biometric Service (WbioSrvc) is running on high-risk hosts and consider disabling it on systems that do not use Windows Hello or other biometric sign-in features. No public PoC or KEV listing exists yet, so routine patch-cycle handling is reasonable for single-user endpoints.

Affected
Microsoft Windows Biometric Service (Windows)
Estimated exposure
mass≈1 billion+ Windows installations (service ships by default with Windows) — The Biometric Service is a default Windows component, so exposure scales with the installed base of Windows devices (commonly cited at roughly 1.4 billion), though actual exploitability requires local access.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.