ZeroHour

CVE-2026-72997

mass

Local Privilege Escalation via Heap Buffer Overflow in Windows Biometric Service

CVSS 3.1
7.8 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-72997 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, a built-in Windows component that handles fingerprint, face, and other biometric authentication. A local attacker who already has authorized, low-privileged access to a system can send crafted input to the service to corrupt heap memory and execute code in the service's context. Successful exploitation yields a full local privilege escalation, giving the attacker high confidentiality, integrity, and availability impact — effectively administrative/SYSTEM-level control of the host. Any Windows system running the affected Biometric Service component is exposed, with the precise affected Windows versions defined in Microsoft's advisory. Exploitation status: none known — there is no public proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns only a 0.3% probability of exploitation within 30 days.

What to do: Track Microsoft's advisory and apply the patch for CVE-2026-72997 as soon as it is released via Windows Update/WSUS, prioritizing multi-user systems where local privilege escalation has the greatest impact (RDS hosts, shared workstations, kiosks, and VDI). Until patching, apply least-privilege practices by limiting which users can log on locally to sensitive machines, and verify the Biometric Service is enabled/running on hosts you need to triage. Because no public PoC or in-the-wild exploitation is known, routine Patch Tuesday remediation is sufficient rather than emergency patching.

Affected
Microsoft Windows (Windows Biometric Service component)
Estimated exposure
mass≈1 billion+ Windows devices (Biometric Service ships as a default component of modern Windows desktop editions) — The Windows Biometric Service is a default OS component on broadly deployed Windows desktop editions, so the potential exposure is on the order of Microsoft's roughly billion-plus device installed base, though only systems providing local…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.