CVE-2026-72991
mass1Heap Buffer Overflow in Windows Biometric Service Enables Local Privilege Escalation
CVE-2026-72991 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, a component shipped with Microsoft Windows. An attacker who already holds a low-privileged account on the machine can feed malicious input to the service, corrupting its heap memory without requiring any user interaction. Successful exploitation allows the attacker to elevate privileges locally, with high impact on confidentiality, integrity, and availability of the system. Any Windows installation running the affected component is exposed; the available data does not specify which Windows version ranges are affected, so defenders should consult Microsoft's advisory for the exact builds. Exploitation status is currently quiet: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS estimates only a 0.3% probability of exploitation within the next 30 days.
What to do: Apply Microsoft's Windows security update addressing CVE-2026-72991 as soon as it is available (the provided data does not identify a specific patched build, so track the Microsoft advisory and Windows Update). Because exploitation requires only a standard local account and no user interaction, prioritize patching shared workstations, multi-user hosts, and systems where untrusted users can log on via RDP or local sessions. No public PoC or in-the-wild exploitation is known, so no urgent compensating controls are required beyond routine patching.
| Microsoft Windows (Windows Biometric Service) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.