CVE-2026-69593
massHeap Buffer Overflow in Windows Biometric Service Enables Local Privilege Escalation
CVE-2026-69593 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, the built-in Windows component that handles biometric authentication such as Windows Hello. A local attacker who already has low-privileged access on the machine can trigger the flaw without any user interaction, corrupting heap memory in the service. Successful exploitation allows the attacker to elevate privileges locally, gaining high impact on the confidentiality, integrity and availability of the host. Any Windows installation running the Biometric Service is in scope, with Microsoft's advisory (CNA: [email protected]) listing the affected releases. As of now there is no public proof of concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS puts 30-day exploitation probability at just 0.3% (25th percentile), indicating no known exploitation.
What to do: Apply Microsoft's security update for CVE-2026-69593 as it becomes available, prioritizing multi-user hosts such as RDS servers, shared workstations and kiosks where local privilege escalation is most valuable. Until systems are patched, restrict interactive/local logon rights on sensitive machines and confirm which endpoints use Windows Hello or other biometric sign-in, since those are the primary attack surface. Check Microsoft's advisory for the precise affected version list before scanning or prioritizing.
| Microsoft Windows (Windows Biometric Service) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.