ZeroHour

CVE-2026-73011

mass

Heap Buffer Overflow in Windows Biometric Service Enables Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p16
Published
()
Modified
AI analysis

Windows Biometric Service, the Windows component that manages fingerprint, face, and other biometric sign-in hardware, contains a heap-based buffer overflow (CWE-122). A low-privileged, authorized local user can trigger the flaw by interacting with the service, corrupting heap memory with no user interaction required. Successful exploitation allows the attacker to elevate privileges locally, with high impact on confidentiality, integrity, and availability of the affected system. Any Windows installation running the Biometric Service, particularly machines using Windows Hello biometric sign-in, is affected. No exploitation in the wild, public proof-of-concept, or KEV listing is known; EPSS is low at 0.2% (16th percentile), and the flaw is assigned by Microsoft.

What to do: Apply Microsoft's security update for CVE-2026-73011 through Windows Update; check Microsoft's advisory to identify which Windows builds in your fleet are affected, prioritizing endpoints where Windows Hello biometric sign-in is enabled. Because exploitation requires local access and no public PoC or in-the-wild exploitation is known, standard patch cycles are reasonable for most organizations. As an interim measure, restrict local logon and unprivileged code execution on high-value Windows hosts, and consider disabling the Biometric Service on systems that do not use biometric sign-in.

Affected
Microsoft Windows Biometric Service (Windows)
Estimated exposure
masshundreds of millions of Windows devices (the Biometric Service ships with Windows and is actively used on Windows Hello-capable machines) — Windows runs on an installed base of over a billion devices and the Biometric Service is present on essentially all modern Windows installations, though practical exposure concentrates on systems with biometric hardware, and exploitation…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.