CVE-2026-73007
massHeap Buffer Overflow in Windows Biometric Service Allows Local Privilege Escalation
CVE-2026-73007 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, the Windows component that handles biometric authentication such as fingerprint sign-in. A local attacker who already has an authorized, low-privileged account on the machine can trigger the overflow with no user interaction, since the attack vector is local and complexity is low. Successful exploitation lets the attacker elevate their privileges locally, with high impact to confidentiality, integrity and availability per the CVSS vector. Any Windows deployment that includes the Windows Biometric Service is potentially affected, but the source data does not specify version ranges, so Microsoft's advisory must be consulted for exact affected builds. No public proof-of-concept is known, the flaw is not in CISA's KEV catalog, and EPSS puts the 30-day exploitation probability at only 0.2% (16th percentile), so no exploitation is currently known.
What to do: Check Microsoft's advisory for the exact affected Windows versions and install the corresponding security update as soon as it is available. Until patching, prioritize shared and multi-user systems (RDS hosts, kiosks, shared workstations) where local low-privileged accounts are common, and restrict local logon rights for untrusted users where feasible. With no public PoC, no KEV listing, and a low EPSS, single-user endpoints on a standard patch cadence face limited near-term risk.
| Microsoft Windows Biometric Service (Windows operating system component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.