ZeroHour

CVE-2026-73000

mass

Heap overflow in Windows Biometric Service enables local privilege escalation

CVSS 3.1
7.8 high
EPSS
<1%p16
Published
()
Modified
AI analysis

CVE-2026-73000 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, the built-in Windows component that handles fingerprint and face authentication (Windows Hello). A local attacker who already has a low-privileged account on a machine can send crafted input to the service, overrunning a heap buffer and gaining the ability to execute code with elevated privileges. Successful exploitation yields full compromise of the local system (high confidentiality, integrity, and confidentiality-adjacent impact under the CVSS vector). Any Windows system with the Biometric Service component is affected; because the service ships with Windows, the potentially affected population is very large, though exploitation requires local access rather than network exposure. There is currently no public proof of concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS estimates only a 0.2% probability of exploitation within 30 days.

What to do: Apply Microsoft's security update for this CVE via Windows Update as soon as it is available; the source data does not identify specific fixed builds, so check Microsoft's advisory for the affected/fixed version list for your Windows release. No workarounds are documented, but prioritizing patching on shared and multi-user systems (where local attackers are most plausible) is prudent, and monitor for updates since local privilege escalations are frequently chained with remote code execution flaws. No public PoC or in-the-wild exploitation is known at this time.

Affected
Microsoft Windows Biometric Service (Microsoft Windows)
Estimated exposure
masshundreds of millions to ~1 billion+ Windows installations (built-in Windows component) — The Biometric Service ships with Windows 10/11, so the affected population is bounded by Microsoft's reported Windows install base of roughly 1.4 billion active devices, though actual exploitability requires local low-privileged access.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.