CVE-2026-73000
massHeap overflow in Windows Biometric Service enables local privilege escalation
CVE-2026-73000 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, the built-in Windows component that handles fingerprint and face authentication (Windows Hello). A local attacker who already has a low-privileged account on a machine can send crafted input to the service, overrunning a heap buffer and gaining the ability to execute code with elevated privileges. Successful exploitation yields full compromise of the local system (high confidentiality, integrity, and confidentiality-adjacent impact under the CVSS vector). Any Windows system with the Biometric Service component is affected; because the service ships with Windows, the potentially affected population is very large, though exploitation requires local access rather than network exposure. There is currently no public proof of concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS estimates only a 0.2% probability of exploitation within 30 days.
What to do: Apply Microsoft's security update for this CVE via Windows Update as soon as it is available; the source data does not identify specific fixed builds, so check Microsoft's advisory for the affected/fixed version list for your Windows release. No workarounds are documented, but prioritizing patching on shared and multi-user systems (where local attackers are most plausible) is prudent, and monitor for updates since local privilege escalations are frequently chained with remote code execution flaws. No public PoC or in-the-wild exploitation is known at this time.
| Microsoft Windows Biometric Service (Microsoft Windows) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.