CVE-2026-72993
massHeap Buffer Overflow in Windows Biometric Service Enables Local Privilege Escalation
CVE-2026-72993 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, the Windows component that brokers Windows Hello fingerprint, face, and credential operations. A local attacker who already holds a low-privileged account on the machine can trigger the overflow by sending crafted input to the service, with no user interaction required (CVSS 3.1: AV:L/AC:L/PR:L/UI:N). Successful exploitation lets the attacker elevate privileges locally, with high impact on confidentiality, integrity, and availability — effectively gaining SYSTEM-level control of the host. All Windows systems running the affected builds are technically exposed, but practical reach is limited because the attacker must already be able to execute code locally on the target. As of now there are no public proof-of-concept exploits, the flaw is not in the CISA KEV catalog, and EPSS assigns only a 0.2% probability of exploitation within 30 days, so no exploitation is known.
What to do: Apply Microsoft's security update for CVE-2026-72993 via the next cumulative Windows update, and check Microsoft's advisory for the exact affected builds since the data does not specify version ranges. Prioritize shared, multi-user, and kiosk/VDI endpoints where untrusted users hold local accounts, as those best match the local privilege escalation scenario. Given the absence of public PoCs, KEV listing, and low EPSS, patching on the regular update cycle is a reasonable cadence for single-user endpoints.
| Microsoft Windows (Windows Biometric Service) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.