ZeroHour

CVE-2026-69738

mass

Local Privilege Escalation via Integer Overflow in Windows Biometric Service

CVSS 3.1
7.8 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-69738 is an integer overflow or wraparound flaw (CWE-190, also mapped to CWE-122) in the Windows Biometric Service, the Windows component that handles biometric logon data such as fingerprint and face authentication. An attacker who already has a valid low-privileged account on a local machine can trigger the flaw by causing the service to process a value that overflows, without any user interaction. Successful exploitation elevates the attacker's privileges locally, with high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.8). All Windows systems running the affected builds of the Windows Biometric Service are exposed, though the specific Windows version ranges were not detailed in the source data. As of this analysis there is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at just 0.3% (25th percentile), indicating no confirmed in-the-wild exploitation yet.

What to do: Apply the Windows cumulative security update from Microsoft that addresses CVE-2026-69738 as soon as it is available via Windows Update, prioritizing shared workstations, kiosks, and servers where multiple low-privileged local accounts exist. Because exploitation requires local access and there is no known public exploit or in-the-wild activity, standard patching cadence is reasonable, but verify after patching that the Windows Biometric Service (WbioSvc) is updated on systems where biometric sign-in is enabled. Until patched, limit untrusted local accounts on sensitive Windows hosts as an interim risk reduction.

Affected
Microsoft Windows Biometric Service (Windows Biometric Service component shipped with Windows client and server operating systems)
Estimated exposure
masshundreds of millions of Windows devices (Biometric Service ships as a default component of Windows) — The Windows Biometric Service is present by default on modern Windows client and server installations, and Microsoft's Windows install base exceeds one billion devices, so the plausibly affected population is on the order of hundreds of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-122, CWE-190
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.