CVE-2026-69787
massLocal Privilege Escalation via Heap Overflow in Windows Biometric Service
CVE-2026-69787 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, the Windows component that handles biometric authentication such as fingerprint and facial-recognition sign-in. A local, authenticated (low-privileged) user can trigger the flaw by sending malformed input to the service, and no user interaction is required. Successful exploitation elevates the attacker's privileges on the local machine; the CVSS impact ratings (C:H/I:H/A:H with scope unchanged) indicate the compromise can produce high confidentiality, integrity, and availability impact on the system. All Windows deployments running the affected Biometric Service are in scope, though the source data does not specify the exact Windows version ranges affected. Exploitation has not been observed: there is no known public proof-of-concept, the CVE is not in CISA's KEV, and EPSS estimates only a 0.3% probability of exploitation within 30 days (25th percentile).
What to do: Install the Microsoft Windows security update addressing CVE-2026-69787 via Windows Update/WSUS as soon as it is offered through your patch channel, prioritizing shared workstations, kiosks, and other multi-user systems where local low-privileged accounts are common. Until patched, check whether Windows Hello or other biometric sign-in is actually used on each host, since disabling the Windows Biometric Service on systems that do not need it removes the attack surface. Watch Microsoft's advisory for the specific affected version ranges, which were not enumerated in the source data.
| Microsoft Windows Biometric Service (Windows component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.