CVE-2026-72941
massMicrosoft Windows Biometric Service Heap Overflow Allows Local Privilege Escalation
CVE-2026-72941 is a heap-based buffer overflow (CWE-122) in the Microsoft Windows Biometric Service. A local attacker who already holds low-privileged credentials on a Windows machine can trigger the flaw by getting the service to process malformed input, corrupting heap memory. Successful exploitation allows the attacker to elevate privileges on the affected host, with high impact on confidentiality, integrity and availability (CVSS 3.1: 7.8). Any Windows system running the affected Windows Biometric Service builds is exposed to this local escalation path; no exploitation is currently known, there is no public PoC, EPSS is a low 0.3%, and the issue is not in CISA KEV.
What to do: Apply Microsoft's security update for this CVE as soon as it is available via Windows Update and consult Microsoft's advisory for the list of affected builds. Until patched, limit local logon rights to trusted users, and if biometric sign-in (Windows Hello) is not used, consider disabling the Windows Biometric Service to shrink the attack surface.
| Microsoft Windows (Windows Biometric Service) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.