CVE-2026-69352
massHeap Buffer Overflow in Windows Biometric Service Enables Local Privilege Escalation
CVE-2026-69352 is a heap-based buffer overflow (root cause: improper input validation, CWE-20/CWE-122) in the Windows Biometric Service, the Windows component that manages biometric sensor access and authentication. An attacker who already holds a low-privileged account on a target machine can trigger the flaw by feeding malformed input to the service, corrupting heap memory without requiring any user interaction. Successful exploitation lets the authorized attacker elevate privileges locally, yielding high-privilege code execution with high confidentiality, integrity, and availability impact on the host. All Windows installations running the affected Windows Biometric Service are exposed to local attackers; the specific affected builds and editions are defined by Microsoft's advisory and are not enumerated in the available data. As of this analysis there is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns only a 0.3% probability of exploitation within 30 days (25th percentile).
What to do: Install Microsoft's security updates for the affected Windows builds as soon as they are available through Windows Update, WSUS, or your patch-management pipeline, and verify against Microsoft's advisory which builds are in scope. Because exploitation requires an existing low-privileged local account, prioritize multi-user systems, Remote Desktop/terminal hosts, and shared workstations where local accounts are widely provisioned. Monitor Microsoft's advisory and threat feeds for a public PoC or KEV addition, which would raise the priority of this patch.
| Microsoft Windows Biometric Service (Windows operating system component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
- Weakness
- CWE-20, CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.