CVE-2026-72990
massMicrosoft Windows Biometric Service Heap Overflow Enables Local Privilege Escalation
CVE-2026-72990 is a heap-based buffer overflow (CWE-122) in the Microsoft Windows Biometric Service, with the CWE mapping also listing CWE-190 (integer overflow or wraparound), indicating a size-calculation error underlies the overflow. An authorized, low-privileged local user can trigger the flaw without any user interaction, causing the service to write past the end of a heap buffer. Successful exploitation allows the attacker to elevate privileges locally, with high impact on the confidentiality, integrity, and availability of the compromised machine. Any Windows system running the Biometric Service is potentially affected, though the provided data does not specify which Windows versions or builds are impacted. There is no public proof-of-concept, the flaw is not in CISA's KEV, and EPSS assigns roughly a 0.3% probability of exploitation within 30 days, so no exploitation is currently known.
What to do: Install Microsoft's security update for CVE-2026-72990 via Windows Update as soon as the advisory identifies the affected builds, prioritizing shared, kiosk, or multi-user machines where untrusted users hold local accounts. Because exploitation requires an authorized local session, review and restrict local logon rights on sensitive hosts as an interim measure. No workarounds or public PoC are currently documented.
| Microsoft Windows Biometric Service (Microsoft Windows) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
- Weakness
- CWE-122, CWE-190
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.