ZeroHour

CVE-2026-69476

mass

Heap-based buffer overflow in Windows Biometric Service allows local privilege escalation

CVSS 3.1
7.8 high
EPSS
<1%p27
Published
()
Modified
AI analysis

CVE-2026-69476 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, the Windows component that handles fingerprint and other biometric authentication. The attack vector is local: per the CVSS vector, a user already authorized on the machine with low privileges can trigger the overflow without any user interaction, although the available data does not detail the exact trigger. A successful exploit lets the attacker elevate privileges on that machine, with high impact on confidentiality, integrity, and availability reflected in the CVSS 3.1 base score of 7.8 (High). Any Windows installation running the vulnerable version of the Biometric Service is potentially affected; the exact affected Windows versions are not specified in the available data and should be taken from Microsoft's advisory. No public proof-of-concept is known, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS currently assigns only a 0.3% probability of exploitation within 30 days.

What to do: Apply Microsoft's security update for this Windows Biometric Service issue as soon as it is available, using Windows Update or your WSUS/Intune/Config Manager patch channels, and verify the affected Windows versions against Microsoft's advisory since they are not enumerated in the summary data here. Until patched, restrict local interactive logon on shared or multi-user Windows hosts to trusted accounts, and consider disabling the Biometric Service on machines that do not use biometric sign-in as a defense-in-depth measure. No in-the-wild exploitation or public PoC is known, but monitor Microsoft's advisory and the CISA KEV catalog for status changes.

Affected
Microsoft Windows Biometric Service (component of Microsoft Windows)
Estimated exposure
masshundreds of millions of Windows devices (the Biometric Service ships by default with Windows) — The Windows Biometric Service is a default component of modern Windows releases, so if Microsoft's advisory covers mainstream editions the potential population is on the order of hundreds of millions of devices (the Windows install base…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.