ZeroHour

CVE-2026-72994

mass

Heap Buffer Overflow in Windows Biometric Service Enables Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p16
Published
()
Modified
AI analysis

CVE-2026-72994 is a heap-based buffer overflow (CWE-122, rooted in improper input validation, CWE-20) in the Microsoft Windows Biometric Service. An authorized attacker with low privileges on the local system can trigger the flaw by supplying crafted input to the service, without user interaction. Successful exploitation lets the attacker elevate privileges on the local machine, with high impact on confidentiality, integrity, and availability. Any Windows system running the Biometric Service (including configurations using Windows Hello biometric authentication) is potentially affected, though only attackers who already have local access can leverage it. There is no known public proof-of-concept, no CISA KEV listing, and no confirmed in-the-wild exploitation; EPSS estimates only a 0.2% probability of exploitation within 30 days.

What to do: Apply the Microsoft Windows security update addressing CVE-2026-72994 as soon as it is available, prioritizing shared or multi-user Windows endpoints where local users are less trusted. Since the vulnerable component is the Biometric Service, deployments that rely on Windows Hello biometric sign-in should be treated as higher priority. Consult Microsoft's advisory for the exact affected builds, as version ranges are not included in the data available here.

Affected
Microsoft Windows Biometric Service (Windows operating system)
Estimated exposure
massHundreds of millions of Windows endpoints ship the Biometric Service (present by default on modern Windows client installations, especially Windows… — The Windows client install base is on the order of a billion devices and the Biometric Service is installed by default on current Windows releases, so the component is broadly deployed, although exploitation requires an attacker with…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-20, CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.