CVE-2026-73015
massLocal Privilege Escalation via Heap Overflow in Microsoft Windows Biometric Service
CVE-2026-73015 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, the Windows component that handles biometric sign-in features such as fingerprint and facial recognition. An attacker who already holds a low-privileged, authorized account on the local machine can trigger the flaw, with no user interaction required, causing the service to overflow a heap buffer. Successful exploitation grants a high-impact elevation of privilege, with full confidentiality, integrity, and availability impact on the host, effectively handing the attacker far greater rights than they started with. Any Windows system shipping the Biometric Service is in scope, though the source data does not specify which Windows builds or versions are affected. There is currently no known exploitation: the flaw is not in CISA KEV, no public proof-of-concept exists, and EPSS estimates only a ~0.2% chance of exploitation in the next 30 days.
What to do: Apply the Microsoft Windows security update that addresses CVE-2026-73015 as soon as it is released, and check Microsoft's advisory for the exact affected builds since they are not enumerated in the available data. Prioritize shared or multi-user endpoints, and especially machines where Windows Hello / biometric sign-in is enabled, since that is where the vulnerable service is actively exercised. Given no known exploitation, no public PoC, and low EPSS (~0.2%), treating this within the normal patch cycle is reasonable absent further threat intelligence.
| Microsoft Windows Biometric Service (Windows operating system) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.