CVE-2026-69580
massHeap Overflow in Microsoft Windows Biometric Service Enables Local Privilege Escalation
CVE-2026-69580 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, the Windows component that handles fingerprint, facial-recognition, and PIN-adjacent biometric logon operations. It is triggered by an authorized local user who sends malformed input to the service, which corrupts heap memory without requiring any user interaction (per the CVSS vector). An attacker who successfully exploits it elevates privileges locally, gaining a more privileged context on the host with high impact on confidentiality, integrity, and availability of the system. Any Windows deployment that includes the Biometric Service is exposed, with highest relevance on endpoints where multiple local accounts or biometric (Windows Hello) logon is enabled, since the attacker must already have a local foothold. There is no evidence of active exploitation so far: EPSS is 0.3% (25th percentile), it is not in CISA KEV, and no public proof-of-concept is known.
What to do: Apply Microsoft's security update for CVE-2026-69580 via Windows Update across client and server fleets as soon as it is available, prioritizing shared systems (RDS hosts, kiosks, multi-user workstations) and endpoints with biometric logon enabled. Where patching is delayed, consider whether the Biometric Service can be disabled or biometric logon restricted on systems that do not need it, and monitor vendor advisories for exploitation updates. No public PoC or in-the-wild exploitation is known at this time.
| Microsoft Windows Biometric Service (ships with Windows client and server editions) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.