CVE-2026-72992
massHeap overflow in Windows Biometric Service enables local privilege escalation
CVE-2026-72992 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, the OS component that supports fingerprint and facial-recognition sign-in. It can be triggered by an authorized local attacker — meaning someone who already holds a low-privileged account or session on the machine — without requiring user interaction. Successful exploitation allows local elevation of privilege with high impact on confidentiality, integrity, and availability, effectively handing the attacker administrative control of the host. Any Windows installation with the Biometric Service enabled is affected; the specific affected Windows builds are not listed in the available data, so defenders should consult Microsoft's advisory for exact version ranges. No public proof-of-concept, CISA KEV listing, or known in-the-wild exploitation exists, and EPSS estimates only a 0.3% probability of exploitation within 30 days.
What to do: Apply Microsoft's security update for CVE-2026-72992 via Windows Update as soon as it is available, checking the Microsoft advisory for the exact affected builds. Prioritize shared workstations, kiosks, and multi-user or terminal-server systems where untrusted users hold local accounts, and verify whether Windows Hello/biometric sign-in is enabled on those hosts. Since exploitation requires local low-privileged access, limiting local user accounts and disabling biometric logon where unnecessary can reduce interim risk.
| Microsoft Windows Biometric Service (Windows operating system component, used by Windows Hello) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.