CVE-2026-73002
massInteger Overflow in Windows Biometric Service Enables Local Privilege Escalation
CVE-2026-73002 is an integer overflow/wraparound flaw (CWE-190) in the Windows Biometric Service, the Windows component that supports biometric sign-in such as fingerprint and facial recognition. A local attacker who already holds a low-privileged authorized account can trigger the flaw without any user interaction. Successful exploitation elevates the attacker's privileges locally, and the CVSS impact ratings indicate the resulting compromise exposes high confidentiality, integrity, and availability impact on the host, typically meaning system-level control. Any Windows installation running the affected Biometric Service is potentially exposed, but the flaw is only reachable by code already executing locally, not remotely by itself. There is currently no public proof of concept, the flaw is not in CISA's KEV catalog, and EPSS assigns a 0.2% probability of exploitation within 30 days, indicating no known exploitation at this time.
What to do: Apply Microsoft's patch for this vulnerability as soon as it is available through Windows Update, prioritizing multi-user hosts, servers, and endpoints where untrusted users can execute code locally, and check Microsoft's advisory for the exact affected builds. Until patched, limit local logon and code-execution rights on shared systems and treat any existing local foothold as a potential path to full privilege escalation; monitor for new PoCs or KEV additions given that local privilege escalation flaws are commonly chained with malware.
| Microsoft Windows (Windows Biometric Service) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
- Weakness
- CWE-190
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.