ZeroHour

CVE-2026-73007

mass

Heap Buffer Overflow in Windows Biometric Service Allows Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p16
Published
()
Modified
AI analysis

CVE-2026-73007 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, the Windows component that handles biometric authentication such as fingerprint sign-in. A local attacker who already has an authorized, low-privileged account on the machine can trigger the overflow with no user interaction, since the attack vector is local and complexity is low. Successful exploitation lets the attacker elevate their privileges locally, with high impact to confidentiality, integrity and availability per the CVSS vector. Any Windows deployment that includes the Windows Biometric Service is potentially affected, but the source data does not specify version ranges, so Microsoft's advisory must be consulted for exact affected builds. No public proof-of-concept is known, the flaw is not in CISA's KEV catalog, and EPSS puts the 30-day exploitation probability at only 0.2% (16th percentile), so no exploitation is currently known.

What to do: Check Microsoft's advisory for the exact affected Windows versions and install the corresponding security update as soon as it is available. Until patching, prioritize shared and multi-user systems (RDS hosts, kiosks, shared workstations) where local low-privileged accounts are common, and restrict local logon rights for untrusted users where feasible. With no public PoC, no KEV listing, and a low EPSS, single-user endpoints on a standard patch cadence face limited near-term risk.

Affected
Microsoft Windows Biometric Service (Windows operating system component)
Estimated exposure
masson the order of 1 billion+ Windows installations (the Biometric Service ships as a built-in Windows component) — Windows runs on well over a billion active devices and the Windows Biometric Service is a standard OS component, so nearly all Windows endpoints contain the vulnerable code; note this is a local privilege escalation, so exposure requires a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.