ZeroHour

CVE-2026-72941

mass

Microsoft Windows Biometric Service Heap Overflow Allows Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-72941 is a heap-based buffer overflow (CWE-122) in the Microsoft Windows Biometric Service. A local attacker who already holds low-privileged credentials on a Windows machine can trigger the flaw by getting the service to process malformed input, corrupting heap memory. Successful exploitation allows the attacker to elevate privileges on the affected host, with high impact on confidentiality, integrity and availability (CVSS 3.1: 7.8). Any Windows system running the affected Windows Biometric Service builds is exposed to this local escalation path; no exploitation is currently known, there is no public PoC, EPSS is a low 0.3%, and the issue is not in CISA KEV.

What to do: Apply Microsoft's security update for this CVE as soon as it is available via Windows Update and consult Microsoft's advisory for the list of affected builds. Until patched, limit local logon rights to trusted users, and if biometric sign-in (Windows Hello) is not used, consider disabling the Windows Biometric Service to shrink the attack surface.

Affected
Microsoft Windows (Windows Biometric Service)
Estimated exposure
masshundreds of millions of Windows devices (the Windows Biometric Service is a standard component of modern Windows releases) — The Windows Biometric Service ships as a core Windows component and Microsoft's publicly reported Windows install base exceeds one billion devices, so even restricting to systems where the service or biometric sign-in is enabled leaves…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.