ZeroHour

CVE-2026-72993

mass

Heap Buffer Overflow in Windows Biometric Service Enables Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p16
Published
()
Modified
AI analysis

CVE-2026-72993 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, the Windows component that brokers Windows Hello fingerprint, face, and credential operations. A local attacker who already holds a low-privileged account on the machine can trigger the overflow by sending crafted input to the service, with no user interaction required (CVSS 3.1: AV:L/AC:L/PR:L/UI:N). Successful exploitation lets the attacker elevate privileges locally, with high impact on confidentiality, integrity, and availability — effectively gaining SYSTEM-level control of the host. All Windows systems running the affected builds are technically exposed, but practical reach is limited because the attacker must already be able to execute code locally on the target. As of now there are no public proof-of-concept exploits, the flaw is not in the CISA KEV catalog, and EPSS assigns only a 0.2% probability of exploitation within 30 days, so no exploitation is known.

What to do: Apply Microsoft's security update for CVE-2026-72993 via the next cumulative Windows update, and check Microsoft's advisory for the exact affected builds since the data does not specify version ranges. Prioritize shared, multi-user, and kiosk/VDI endpoints where untrusted users hold local accounts, as those best match the local privilege escalation scenario. Given the absence of public PoCs, KEV listing, and low EPSS, patching on the regular update cycle is a reasonable cadence for single-user endpoints.

Affected
Microsoft Windows (Windows Biometric Service)
Estimated exposure
masshundreds of millions of Windows installs (service ships by default with Windows) — The Windows Biometric Service is a default component of Windows 10/11 client and Windows Server editions, whose combined install base is on the order of a billion devices, and no version scoping in the data narrows that down, though actual…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.