ZeroHour

CVE-2026-69583

mass

Local Privilege Escalation via Heap Overflow in Microsoft Windows Biometric Service

CVSS 3.1
7.8 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-69583 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, the Windows component that handles biometric authentication (Windows Hello) on the local machine. A local attacker who is already authorized to run code with low privileges on the system can trigger the overflow, per Microsoft's description of the flaw as exploitable by an 'authorized attacker'. Successful exploitation elevates the attacker's privileges on the local system, with high impact to confidentiality, integrity, and availability per the CVSS scoring (7.8). All Windows installations that include the Biometric Service are potentially affected, but the available data does not specify which Windows versions or builds are in scope, so defenders should consult Microsoft's advisory for exact ranges. There is currently no known exploitation: the flaw is not in CISA's KEV, no public proof-of-concept is known, and EPSS assigns a 0.3% probability of exploitation within 30 days (25th percentile).

What to do: Apply Microsoft's security update for CVE-2026-69583 and check Microsoft's advisory for the exact affected and patched Windows builds, since the source data here does not list version ranges. Until patched, restrict local interactive sign-in on shared or multi-user systems (kiosks, shared workstations, Remote Desktop session hosts) to trusted accounts, as exploitation requires an authorized local user. Given the absence of a public PoC, no KEV listing, and a low EPSS score (0.3%), this can be handled within your normal monthly patching cycle.

Affected
Microsoft Windows (Windows Biometric Service component)
Estimated exposure
masshundreds of millions of Windows installations (the Biometric Service ships as a standard component of mainstream Windows releases) — Windows runs on over a billion active devices and the Biometric Service is present by default on mainstream Windows releases, so plausible exposure is on the order of hundreds of millions of installations, though only hosts where local…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.