ZeroHour

CVE-2026-72996

mass

Heap Buffer Overflow in Windows Biometric Service Allows Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-72996 is a heap-based buffer overflow (CWE-122, preceded by improper input validation per CWE-20) in the Windows Biometric Service, a component maintained by Microsoft. A local attacker who already holds a valid low-privileged account on the machine can trigger the flaw by getting maliciously crafted input processed by the service, without any user interaction. Successful exploitation allows the attacker to elevate privileges on the local system, with high impact on confidentiality, integrity, and availability. Any Windows installation running the affected Biometric Service is exposed, though exploitation requires local code execution rather than a network foothold. There is currently no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at just 0.3% (25th percentile).

What to do: Check Microsoft's advisory for the affected builds and apply the corresponding security update as soon as it ships in your normal patch cycle. Prioritize systems where untrusted or low-privilege users can log on locally, such as shared workstations, kiosks, and multi-user/RDS hosts, and check whether the Biometric Service (WbioSrvc) is running on those systems. Because exploitation requires local access and there is no known public exploit, internet-facing exposure is not a primary concern; focus on lateral-movement hardening and timely patching.

Affected
Microsoft Windows Biometric Service
Estimated exposure
massplausibly hundreds of millions of Windows devices ship this OS component, though the exact affected version range is unknown — The Biometric Service is a default Windows component and Windows runs on well over a billion active devices, so the upper bound on affected installations is enormous, but actual scope depends on the version range in Microsoft's advisory,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-20, CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.