CVE-2026-69589
massHeap-Based Buffer Overflow in Microsoft Windows Biometric Service Enables Local EoP
CVE-2026-69589 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, the Windows component that handles fingerprint and face authentication data. An attacker who already holds an authorized, low-privileged account on the machine can trigger the overflow through the service, with no user interaction required. Successful exploitation yields local elevation of privilege with high impact on confidentiality, integrity, and availability on the affected host. All Windows installations running the Biometric Service are in scope, although Microsoft has not published specific affected version ranges in the available data. Exploitation status is currently quiet: there is no known public proof-of-concept, the flaw is not in CISA's KEV, and EPSS assigns only a ~0.3% chance of exploitation within 30 days.
What to do: Apply Microsoft's security update for CVE-2026-69589 via Windows Update as soon as your environment's patching cycle allows; no workaround or public PoC is known. Prioritize hosts where untrusted users hold local accounts, such as shared workstations, kiosks, and multi-user or RDS systems, since exploitation requires local access. Verify that the update is deployed by confirming the applicable Windows patch level against Microsoft's advisory once version details are published.
| Microsoft Windows Biometric Service (Windows) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.