ZeroHour

CVE-2026-72992

mass

Heap overflow in Windows Biometric Service enables local privilege escalation

CVSS 3.1
7.8 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-72992 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, the OS component that supports fingerprint and facial-recognition sign-in. It can be triggered by an authorized local attacker — meaning someone who already holds a low-privileged account or session on the machine — without requiring user interaction. Successful exploitation allows local elevation of privilege with high impact on confidentiality, integrity, and availability, effectively handing the attacker administrative control of the host. Any Windows installation with the Biometric Service enabled is affected; the specific affected Windows builds are not listed in the available data, so defenders should consult Microsoft's advisory for exact version ranges. No public proof-of-concept, CISA KEV listing, or known in-the-wild exploitation exists, and EPSS estimates only a 0.3% probability of exploitation within 30 days.

What to do: Apply Microsoft's security update for CVE-2026-72992 via Windows Update as soon as it is available, checking the Microsoft advisory for the exact affected builds. Prioritize shared workstations, kiosks, and multi-user or terminal-server systems where untrusted users hold local accounts, and verify whether Windows Hello/biometric sign-in is enabled on those hosts. Since exploitation requires local low-privileged access, limiting local user accounts and disabling biometric logon where unnecessary can reduce interim risk.

Affected
Microsoft Windows Biometric Service (Windows operating system component, used by Windows Hello)
Estimated exposure
mass≈1 billion+ Windows devices (Biometric Service ships as a standard Windows component) — The Windows Biometric Service is a built-in component of Windows 10/11, whose combined installed base exceeds one billion devices, so exposure at the order-of-magnitude level is effectively the entire Windows fleet, though practical risk…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.