CVE-2026-69727
massHeap-Based Buffer Overflow in Windows Biometric Service Enables Privilege Escalation
A heap-based buffer overflow (CWE-122) exists in the Windows Biometric Service, the Windows component that manages biometric sensor data for sign-in features such as Windows Hello. Per Microsoft's description, an authorized (authenticated) attacker can trigger the overflow over a network; the CVSS vector indicates low privileges and user interaction are required. Successful exploitation allows the attacker to elevate privileges, with high impact on confidentiality, integrity, and availability on the target system. Windows installations that ship the Biometric Service are potentially affected, though Microsoft's advisory (not included in the data available here) defines the specific affected builds. No public proof-of-concept is known, the flaw is not in CISA's KEV, and EPSS estimates only a 0.7% probability of exploitation within 30 days, so no exploitation is currently known.
What to do: Apply the Windows security update for CVE-2026-69727 from Microsoft's advisory once available via Windows Update, and check the advisory for the definitive list of affected builds. Prioritize hosts where biometric sign-in is enabled and where unprivileged users sign in remotely (e.g., RDP or VDI environments). Monitor the issue for movement in EPSS or a CISA KEV listing as a signal of active exploitation.
| Microsoft Windows (Windows Biometric Service component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges over a network.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.