CVE-2026-72988
massLocal Privilege Escalation via Heap Buffer Overflow in Windows Biometric Service
CVE-2026-72988 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, the component that processes fingerprint, facial, and other biometric sign-in data for Windows Hello. An attacker who already has a low-privileged local account on a machine would trigger the flaw by getting the service to process malformed or oversized data, overrunning a heap buffer with no user interaction required. Because the Biometric Service runs with SYSTEM-level rights, successful exploitation lets the attacker elevate from a standard local user to full SYSTEM privileges on that machine. Any Windows system where the Biometric Service is running — typically devices equipped with Windows Hello-capable hardware such as fingerprint readers or infrared cameras — is potentially affected. Exploitation status: no public proof-of-concept is known, the flaw is not in CISA's KEV catalog, and EPSS assigns only a 0.2% chance of exploitation within 30 days, so it is currently considered a patch-priority LPE rather than an actively exploited threat.
What to do: Apply the Microsoft security update addressing CVE-2026-72988 through Windows Update as soon as it is available for your Windows editions, prioritizing shared workstations, kiosks, and other systems where untrusted local users can sign in. Until patched, as a mitigation consider disabling the Biometric Service on machines that do not need Windows Hello sign-in, and inventory which endpoints have biometric hardware or enrolled Windows Hello credentials. Monitor Microsoft's advisory for the definitive list of affected builds and any updates to exploitation status.
| Microsoft Windows (Biometric Service / Windows Hello component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.