ZeroHour

CVE-2026-69593

mass

Heap Buffer Overflow in Windows Biometric Service Enables Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-69593 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, the built-in Windows component that handles biometric authentication such as Windows Hello. A local attacker who already has low-privileged access on the machine can trigger the flaw without any user interaction, corrupting heap memory in the service. Successful exploitation allows the attacker to elevate privileges locally, gaining high impact on the confidentiality, integrity and availability of the host. Any Windows installation running the Biometric Service is in scope, with Microsoft's advisory (CNA: [email protected]) listing the affected releases. As of now there is no public proof of concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS puts 30-day exploitation probability at just 0.3% (25th percentile), indicating no known exploitation.

What to do: Apply Microsoft's security update for CVE-2026-69593 as it becomes available, prioritizing multi-user hosts such as RDS servers, shared workstations and kiosks where local privilege escalation is most valuable. Until systems are patched, restrict interactive/local logon rights on sensitive machines and confirm which endpoints use Windows Hello or other biometric sign-in, since those are the primary attack surface. Check Microsoft's advisory for the precise affected version list before scanning or prioritizing.

Affected
Microsoft Windows (Windows Biometric Service)
Estimated exposure
masshundreds of millions of Windows installations (the Biometric Service ships as a built-in component of Windows) — The Windows Biometric Service is included by default in Windows client operating systems, which run on roughly 1.4 billion active devices worldwide, though practical exploitability additionally requires the attacker to obtain a local user…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.