CVE-2026-69489
massHeap Buffer Overflow in Windows Biometric Service Enables Local Privilege Escalation
CVE-2026-69489 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, a built-in component of Microsoft Windows used for biometric authentication such as Windows Hello. It is triggered locally: an attacker who already has an authorized (low-privileged) account on the target machine can cause a heap buffer overflow in the service with no user interaction required, per the CVSS vector (AV:L/PR:L/UI:N). Successful exploitation elevates the attacker's privileges locally, with high impact on confidentiality, integrity, and availability on the compromised host, consistent with gaining administrative-level access. Any Windows system running the affected Biometric Service build is exposed, with the exact affected Windows versions enumerated in Microsoft's advisory; notably, this is a local privilege escalation, not a remotely exploitable flaw. Exploitation status is currently quiet: it is not in CISA KEV, there is no public proof-of-concept, and EPSS estimates only a 0.3% chance of exploitation within 30 days (25th percentile).
What to do: Apply Microsoft's security update for CVE-2026-69489 via Windows Update as soon as it is available, checking Microsoft's advisory for the list of affected builds. Prioritize shared workstations, kiosks, RDP/VDI hosts, and other systems where multiple or untrusted local users can sign in, since those are the environments where a local privilege escalation matters most. No public PoC or documented workaround exists; as an interim measure, restricting local logon rights on sensitive hosts reduces exposure.
| Microsoft Windows (Windows Biometric Service) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.