CVE-2026-69476
massHeap-based buffer overflow in Windows Biometric Service allows local privilege escalation
CVE-2026-69476 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, the Windows component that handles fingerprint and other biometric authentication. The attack vector is local: per the CVSS vector, a user already authorized on the machine with low privileges can trigger the overflow without any user interaction, although the available data does not detail the exact trigger. A successful exploit lets the attacker elevate privileges on that machine, with high impact on confidentiality, integrity, and availability reflected in the CVSS 3.1 base score of 7.8 (High). Any Windows installation running the vulnerable version of the Biometric Service is potentially affected; the exact affected Windows versions are not specified in the available data and should be taken from Microsoft's advisory. No public proof-of-concept is known, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS currently assigns only a 0.3% probability of exploitation within 30 days.
What to do: Apply Microsoft's security update for this Windows Biometric Service issue as soon as it is available, using Windows Update or your WSUS/Intune/Config Manager patch channels, and verify the affected Windows versions against Microsoft's advisory since they are not enumerated in the summary data here. Until patched, restrict local interactive logon on shared or multi-user Windows hosts to trusted accounts, and consider disabling the Biometric Service on machines that do not use biometric sign-in as a defense-in-depth measure. No in-the-wild exploitation or public PoC is known, but monitor Microsoft's advisory and the CISA KEV catalog for status changes.
| Microsoft Windows Biometric Service (component of Microsoft Windows) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.