ZeroHour

CVE-2026-69589

mass

Heap-Based Buffer Overflow in Microsoft Windows Biometric Service Enables Local EoP

CVSS 3.1
7.8 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-69589 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, the Windows component that handles fingerprint and face authentication data. An attacker who already holds an authorized, low-privileged account on the machine can trigger the overflow through the service, with no user interaction required. Successful exploitation yields local elevation of privilege with high impact on confidentiality, integrity, and availability on the affected host. All Windows installations running the Biometric Service are in scope, although Microsoft has not published specific affected version ranges in the available data. Exploitation status is currently quiet: there is no known public proof-of-concept, the flaw is not in CISA's KEV, and EPSS assigns only a ~0.3% chance of exploitation within 30 days.

What to do: Apply Microsoft's security update for CVE-2026-69589 via Windows Update as soon as your environment's patching cycle allows; no workaround or public PoC is known. Prioritize hosts where untrusted users hold local accounts, such as shared workstations, kiosks, and multi-user or RDS systems, since exploitation requires local access. Verify that the update is deployed by confirming the applicable Windows patch level against Microsoft's advisory once version details are published.

Affected
Microsoft Windows Biometric Service (Windows)
Estimated exposure
masshundreds of millions of Windows installations (Biometric Service ships by default with Windows client) — The Windows Biometric Service is a default component of Windows client editions, an installed base commonly estimated in the hundreds of millions to over a billion devices, though exploitation additionally requires the attacker to already…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.