CVE-2026-72994
massHeap Buffer Overflow in Windows Biometric Service Enables Local Privilege Escalation
CVE-2026-72994 is a heap-based buffer overflow (CWE-122, rooted in improper input validation, CWE-20) in the Microsoft Windows Biometric Service. An authorized attacker with low privileges on the local system can trigger the flaw by supplying crafted input to the service, without user interaction. Successful exploitation lets the attacker elevate privileges on the local machine, with high impact on confidentiality, integrity, and availability. Any Windows system running the Biometric Service (including configurations using Windows Hello biometric authentication) is potentially affected, though only attackers who already have local access can leverage it. There is no known public proof-of-concept, no CISA KEV listing, and no confirmed in-the-wild exploitation; EPSS estimates only a 0.2% probability of exploitation within 30 days.
What to do: Apply the Microsoft Windows security update addressing CVE-2026-72994 as soon as it is available, prioritizing shared or multi-user Windows endpoints where local users are less trusted. Since the vulnerable component is the Biometric Service, deployments that rely on Windows Hello biometric sign-in should be treated as higher priority. Consult Microsoft's advisory for the exact affected builds, as version ranges are not included in the data available here.
| Microsoft Windows Biometric Service (Windows operating system) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
- Weakness
- CWE-20, CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.