CVE-2026-73011
massHeap Buffer Overflow in Windows Biometric Service Enables Local Privilege Escalation
Windows Biometric Service, the Windows component that manages fingerprint, face, and other biometric sign-in hardware, contains a heap-based buffer overflow (CWE-122). A low-privileged, authorized local user can trigger the flaw by interacting with the service, corrupting heap memory with no user interaction required. Successful exploitation allows the attacker to elevate privileges locally, with high impact on confidentiality, integrity, and availability of the affected system. Any Windows installation running the Biometric Service, particularly machines using Windows Hello biometric sign-in, is affected. No exploitation in the wild, public proof-of-concept, or KEV listing is known; EPSS is low at 0.2% (16th percentile), and the flaw is assigned by Microsoft.
What to do: Apply Microsoft's security update for CVE-2026-73011 through Windows Update; check Microsoft's advisory to identify which Windows builds in your fleet are affected, prioritizing endpoints where Windows Hello biometric sign-in is enabled. Because exploitation requires local access and no public PoC or in-the-wild exploitation is known, standard patch cycles are reasonable for most organizations. As an interim measure, restrict local logon and unprivileged code execution on high-value Windows hosts, and consider disabling the Biometric Service on systems that do not use biometric sign-in.
| Microsoft Windows Biometric Service (Windows) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.