CVE-2026-72997
massLocal Privilege Escalation via Heap Buffer Overflow in Windows Biometric Service
CVE-2026-72997 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, a built-in Windows component that handles fingerprint, face, and other biometric authentication. A local attacker who already has authorized, low-privileged access to a system can send crafted input to the service to corrupt heap memory and execute code in the service's context. Successful exploitation yields a full local privilege escalation, giving the attacker high confidentiality, integrity, and availability impact — effectively administrative/SYSTEM-level control of the host. Any Windows system running the affected Biometric Service component is exposed, with the precise affected Windows versions defined in Microsoft's advisory. Exploitation status: none known — there is no public proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns only a 0.3% probability of exploitation within 30 days.
What to do: Track Microsoft's advisory and apply the patch for CVE-2026-72997 as soon as it is released via Windows Update/WSUS, prioritizing multi-user systems where local privilege escalation has the greatest impact (RDS hosts, shared workstations, kiosks, and VDI). Until patching, apply least-privilege practices by limiting which users can log on locally to sensitive machines, and verify the Biometric Service is enabled/running on hosts you need to triage. Because no public PoC or in-the-wild exploitation is known, routine Patch Tuesday remediation is sufficient rather than emergency patching.
| Microsoft Windows (Windows Biometric Service component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.