ZeroHour

CVE-2026-72995

mass

Heap Buffer Overflow in Windows Biometric Service Enables Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p16
Published
()
Modified
AI analysis

CVE-2026-72995 is a heap-based buffer overflow (CWE-122, likely reached via an integer overflow or wraparound condition, CWE-190) in the Windows Biometric Service, the Windows component that processes fingerprint and other biometric authentication requests. An authorized local user can trigger the flaw by sending crafted input to the service, corrupting heap memory without requiring any user interaction. Successful exploitation allows the attacker to elevate privileges locally, with high impact on confidentiality, integrity, and availability (CVSS 3.1 score 7.8, vector AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Any Windows installation running the affected Biometric Service, particularly systems using Windows Hello or attached fingerprint/face readers, is affected. No exploitation has been observed: there is no public proof-of-concept, the flaw is not in CISA KEV, and EPSS is low at 0.2% (16th percentile).

What to do: Apply Microsoft's security update for CVE-2026-72995 as soon as it is released, via Windows Update, WSUS, or your patch management pipeline, prioritizing endpoints with fingerprint/face readers or Windows Hello enabled. Until patched, restrict local standard-user access on shared or multi-user workstations. Given no known exploitation, no public PoC, and low EPSS (0.2%), routine patch-cycle handling is reasonable, but monitor the Microsoft advisory for the list of affected builds.

Affected
Microsoft Windows (Windows Biometric Service component)
Estimated exposure
massplausibly hundreds of millions of Windows endpoints (Biometric Service is a standard Windows client component; Windows' installed base exceeds 1 billion… — The Windows Biometric Service ships with Windows client editions and Microsoft's installed base is over a billion devices, so affected installs are likely in the hundreds of millions, though practical exploitation requires local access and…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-122, CWE-190
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.