CVE-2026-72996
massHeap Buffer Overflow in Windows Biometric Service Allows Local Privilege Escalation
CVE-2026-72996 is a heap-based buffer overflow (CWE-122, preceded by improper input validation per CWE-20) in the Windows Biometric Service, a component maintained by Microsoft. A local attacker who already holds a valid low-privileged account on the machine can trigger the flaw by getting maliciously crafted input processed by the service, without any user interaction. Successful exploitation allows the attacker to elevate privileges on the local system, with high impact on confidentiality, integrity, and availability. Any Windows installation running the affected Biometric Service is exposed, though exploitation requires local code execution rather than a network foothold. There is currently no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at just 0.3% (25th percentile).
What to do: Check Microsoft's advisory for the affected builds and apply the corresponding security update as soon as it ships in your normal patch cycle. Prioritize systems where untrusted or low-privilege users can log on locally, such as shared workstations, kiosks, and multi-user/RDS hosts, and check whether the Biometric Service (WbioSrvc) is running on those systems. Because exploitation requires local access and there is no known public exploit, internet-facing exposure is not a primary concern; focus on lateral-movement hardening and timely patching.
| Microsoft Windows Biometric Service | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
- Weakness
- CWE-20, CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.