ZeroHour

CVE-2026-72990

mass

Microsoft Windows Biometric Service Heap Overflow Enables Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-72990 is a heap-based buffer overflow (CWE-122) in the Microsoft Windows Biometric Service, with the CWE mapping also listing CWE-190 (integer overflow or wraparound), indicating a size-calculation error underlies the overflow. An authorized, low-privileged local user can trigger the flaw without any user interaction, causing the service to write past the end of a heap buffer. Successful exploitation allows the attacker to elevate privileges locally, with high impact on the confidentiality, integrity, and availability of the compromised machine. Any Windows system running the Biometric Service is potentially affected, though the provided data does not specify which Windows versions or builds are impacted. There is no public proof-of-concept, the flaw is not in CISA's KEV, and EPSS assigns roughly a 0.3% probability of exploitation within 30 days, so no exploitation is currently known.

What to do: Install Microsoft's security update for CVE-2026-72990 via Windows Update as soon as the advisory identifies the affected builds, prioritizing shared, kiosk, or multi-user machines where untrusted users hold local accounts. Because exploitation requires an authorized local session, review and restrict local logon rights on sensitive hosts as an interim measure. No workarounds or public PoC are currently documented.

Affected
Microsoft Windows Biometric Service (Microsoft Windows)
Estimated exposure
masshundreds of millions of Windows endpoints (the Biometric Service ships with Windows, which runs on >1B devices) — The Windows Biometric Service is a default Windows component and public market data puts the Windows installed base at well over one billion devices, though actual exploitability likely requires biometric-capable hardware (fingerprint…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-122, CWE-190
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.