CVE-2026-72995
massHeap Buffer Overflow in Windows Biometric Service Enables Local Privilege Escalation
CVE-2026-72995 is a heap-based buffer overflow (CWE-122, likely reached via an integer overflow or wraparound condition, CWE-190) in the Windows Biometric Service, the Windows component that processes fingerprint and other biometric authentication requests. An authorized local user can trigger the flaw by sending crafted input to the service, corrupting heap memory without requiring any user interaction. Successful exploitation allows the attacker to elevate privileges locally, with high impact on confidentiality, integrity, and availability (CVSS 3.1 score 7.8, vector AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Any Windows installation running the affected Biometric Service, particularly systems using Windows Hello or attached fingerprint/face readers, is affected. No exploitation has been observed: there is no public proof-of-concept, the flaw is not in CISA KEV, and EPSS is low at 0.2% (16th percentile).
What to do: Apply Microsoft's security update for CVE-2026-72995 as soon as it is released, via Windows Update, WSUS, or your patch management pipeline, prioritizing endpoints with fingerprint/face readers or Windows Hello enabled. Until patched, restrict local standard-user access on shared or multi-user workstations. Given no known exploitation, no public PoC, and low EPSS (0.2%), routine patch-cycle handling is reasonable, but monitor the Microsoft advisory for the list of affected builds.
| Microsoft Windows (Windows Biometric Service component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
- Weakness
- CWE-122, CWE-190
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.