CVE-2026-69583
massLocal Privilege Escalation via Heap Overflow in Microsoft Windows Biometric Service
CVE-2026-69583 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, the Windows component that handles biometric authentication (Windows Hello) on the local machine. A local attacker who is already authorized to run code with low privileges on the system can trigger the overflow, per Microsoft's description of the flaw as exploitable by an 'authorized attacker'. Successful exploitation elevates the attacker's privileges on the local system, with high impact to confidentiality, integrity, and availability per the CVSS scoring (7.8). All Windows installations that include the Biometric Service are potentially affected, but the available data does not specify which Windows versions or builds are in scope, so defenders should consult Microsoft's advisory for exact ranges. There is currently no known exploitation: the flaw is not in CISA's KEV, no public proof-of-concept is known, and EPSS assigns a 0.3% probability of exploitation within 30 days (25th percentile).
What to do: Apply Microsoft's security update for CVE-2026-69583 and check Microsoft's advisory for the exact affected and patched Windows builds, since the source data here does not list version ranges. Until patched, restrict local interactive sign-in on shared or multi-user systems (kiosks, shared workstations, Remote Desktop session hosts) to trusted accounts, as exploitation requires an authorized local user. Given the absence of a public PoC, no KEV listing, and a low EPSS score (0.3%), this can be handled within your normal monthly patching cycle.
| Microsoft Windows (Windows Biometric Service component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.