ZeroHour

CVE-2026-72991

mass1

Heap Buffer Overflow in Windows Biometric Service Enables Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-72991 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, a component shipped with Microsoft Windows. An attacker who already holds a low-privileged account on the machine can feed malicious input to the service, corrupting its heap memory without requiring any user interaction. Successful exploitation allows the attacker to elevate privileges locally, with high impact on confidentiality, integrity, and availability of the system. Any Windows installation running the affected component is exposed; the available data does not specify which Windows version ranges are affected, so defenders should consult Microsoft's advisory for the exact builds. Exploitation status is currently quiet: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS estimates only a 0.3% probability of exploitation within the next 30 days.

What to do: Apply Microsoft's Windows security update addressing CVE-2026-72991 as soon as it is available (the provided data does not identify a specific patched build, so track the Microsoft advisory and Windows Update). Because exploitation requires only a standard local account and no user interaction, prioritize patching shared workstations, multi-user hosts, and systems where untrusted users can log on via RDP or local sessions. No public PoC or in-the-wild exploitation is known, so no urgent compensating controls are required beyond routine patching.

Affected
Microsoft Windows (Windows Biometric Service)
Estimated exposure
masshundreds of millions of Windows devices (Windows Biometric Service ships as a default component of Windows) — The Windows Biometric Service is included by default in Windows installations, so the plausible exposed population roughly tracks the Windows installed base of hundreds of millions of devices, though the true count depends on which builds…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.