ZeroHour

CVE-2026-70581

mass

Integer overflow local privilege escalation in Microsoft Windows Biometric Service

CVSS 3.1
7.8 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-70581 is an integer overflow/wraparound flaw (CWE-190, alongside CWE-20 improper input validation) in the Windows Biometric Service, the built-in Windows component that handles fingerprint, face, and other biometric authentication. A local, already-authorized low-privileged attacker can trigger the overflow by getting the service to process input that exceeds its internal integer limits, corrupting memory without requiring any user interaction. Successful exploitation allows the attacker to elevate privileges locally, gaining high-impact access to confidentiality, integrity, and availability of the host (CVSS 3.1: 7.8, AV:L/AC:L/PR:L/UI:N). Exposure is broad because the Biometric Service ships as a default Windows component, though the source data does not specify exact affected Windows builds or versions, so Microsoft's advisory governs there. No public proof-of-concept is known, the flaw is not in CISA's KEV catalog, and EPSS is low (0.3% probability of exploitation in 30 days, 25th percentile), indicating no confirmed exploitation so far.

What to do: Apply Microsoft's security update for CVE-2026-70581 via Windows Update as soon as it is released, checking Microsoft's advisory for the exact affected builds in your estate. Prioritize hosts where local privilege escalation has outsized impact — multi-user servers, RDP/jump hosts, kiosks, and shared workstations — since no public PoC or in-the-wild exploitation is known and EPSS is low. No specific workarounds are documented in the provided data; confirm the service is enabled/patched on biometric sign-in deployments and monitor for updates to Microsoft's guidance.

Affected
Microsoft Windows Biometric Service (Windows client and server editions)
Estimated exposure
mass≈1 billion+ Windows installations (Biometric Service is a default OS component) — The Windows Biometric Service ships by default with Windows desktop and server operating systems, which run on well over a billion active devices worldwide, although exploitation requires local code execution by an authenticated user…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-20, CWE-190
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.