CVE-2026-73001
massHeap Buffer Overflow in Windows Biometric Service Enables Local Privilege Escalation
CVE-2026-73001 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, a built-in Windows component that handles biometric authentication such as Windows Hello. A low-privileged, authorized local attacker can trigger the flaw by interacting with the service, and the CVSS vector confirms no user interaction and no remote access are required. Successful exploitation lets the attacker elevate privileges on the local machine with high impact on confidentiality, integrity, and availability, which on Windows typically means gaining elevated rights beyond the compromised account. Any Windows system running the affected Biometric Service code is in scope; Microsoft has not published the affected build ranges in the available data, so consult Microsoft's advisory. Exploitation status is quiet: there is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS puts 30-day exploitation probability at just 0.3%.
What to do: Track Microsoft's advisory for CVE-2026-73001 and apply the corresponding Windows security update as soon as it is released, since no fixed build numbers are available in the current data. Given the lack of a public PoC, absence from CISA KEV, and low EPSS, this can follow your normal monthly patch cycle rather than emergency patching, but prioritize it because Windows local privilege escalations are frequently chained with other flaws for full compromise. On endpoints, confirm whether biometric sign-in (Windows Hello / the WbioSrvc service) is in use; where it is not needed, consider disabling it as an interim risk reduction.
| Microsoft Windows Biometric Service (Windows operating systems) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.