CVE-2026-69773
massHeap Buffer Overflow in Windows Biometric Service Enables Privilege Escalation
CVE-2026-69773 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, the Windows component that handles biometric authentication such as Windows Hello fingerprint and facial recognition. Per the CVSS vector, an authorized attacker holding valid low-privileged credentials can trigger the flaw over a network with low attack complexity, though user interaction is required, making a remote interactive session (e.g., remote logon) the likely attack path. Successful exploitation allows the attacker to elevate privileges on the targeted host, with high impact on the confidentiality, integrity, and availability of that system. Any Windows system running the Biometric Service is potentially affected, with risk concentrated on machines where biometric authentication is enrolled; the available data does not enumerate specific affected Windows versions. Exploitation has not been observed: there is no public proof-of-concept, the CVE is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS estimates only a ~0.7% chance of exploitation in the next 30 days (51st percentile).
What to do: Apply Microsoft's security update for CVE-2026-69773 as soon as it is released, checking the Microsoft advisory for the correct servicing update for each Windows release in your fleet. Until patched, reduce exposure by restricting remote interactive access (e.g., limit RDP/remote logon to VPN and managed accounts) and consider disabling the Biometric Service on systems that do not use Windows Hello. Monitor Microsoft advisories for any change in exploitation status, since no public PoC or in-the-wild activity is currently known.
| Microsoft Windows Biometric Service (Windows component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges over a network.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.