CVE-2026-69323
massHeap Buffer Overflow in Windows Biometric Service Enables Local Privilege Escalation
CVE-2026-69323 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, a built-in Windows component. A low-privileged, already-authorized local attacker can trigger the flaw without user interaction by interacting with the service in a way that overflows a heap buffer. Successful exploitation lets the attacker elevate privileges locally, gaining high integrity-level access with potential for full confidentiality, integrity, and availability impact on the host. Any Windows system running the Biometric Service is affected, with shared or multi-user Windows hosts and kiosks the most meaningful attack surface since exploitation requires local access. No public proof-of-concept, KEV listing, or known in-the-wild exploitation is currently reported, and EPSS assigns a low 0.3% probability of exploitation within 30 days.
What to do: Install Microsoft's security update addressing CVE-2026-69323 as soon as it is available, prioritizing shared Windows hosts, kiosks, and remote-workstation servers where untrusted users hold local logon rights. As an interim check, determine whether the Biometric Service (WbioSrvc) is running on high-risk hosts and consider disabling it on systems that do not use Windows Hello or other biometric sign-in features. No public PoC or KEV listing exists yet, so routine patch-cycle handling is reasonable for single-user endpoints.
| Microsoft Windows Biometric Service (Windows) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.