ZeroHour

CVE-2026-69489

mass

Heap Buffer Overflow in Windows Biometric Service Enables Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-69489 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, a built-in component of Microsoft Windows used for biometric authentication such as Windows Hello. It is triggered locally: an attacker who already has an authorized (low-privileged) account on the target machine can cause a heap buffer overflow in the service with no user interaction required, per the CVSS vector (AV:L/PR:L/UI:N). Successful exploitation elevates the attacker's privileges locally, with high impact on confidentiality, integrity, and availability on the compromised host, consistent with gaining administrative-level access. Any Windows system running the affected Biometric Service build is exposed, with the exact affected Windows versions enumerated in Microsoft's advisory; notably, this is a local privilege escalation, not a remotely exploitable flaw. Exploitation status is currently quiet: it is not in CISA KEV, there is no public proof-of-concept, and EPSS estimates only a 0.3% chance of exploitation within 30 days (25th percentile).

What to do: Apply Microsoft's security update for CVE-2026-69489 via Windows Update as soon as it is available, checking Microsoft's advisory for the list of affected builds. Prioritize shared workstations, kiosks, RDP/VDI hosts, and other systems where multiple or untrusted local users can sign in, since those are the environments where a local privilege escalation matters most. No public PoC or documented workaround exists; as an interim measure, restricting local logon rights on sensitive hosts reduces exposure.

Affected
Microsoft Windows (Windows Biometric Service)
Estimated exposure
masshundreds of millions to ~1 billion Windows installations ship the affected component (local exploitation only, no network exposure) — Windows 10/11 runs on well over a billion devices and the Biometric Service is a default OS component (active wherever biometric hardware or Windows Hello is configured), though exploitation requires an existing local account rather than…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.