ZeroHour

CVE-2026-73015

mass

Local Privilege Escalation via Heap Overflow in Microsoft Windows Biometric Service

CVSS 3.1
7.8 high
EPSS
<1%p16
Published
()
Modified
AI analysis

CVE-2026-73015 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, the Windows component that handles biometric sign-in features such as fingerprint and facial recognition. An attacker who already holds a low-privileged, authorized account on the local machine can trigger the flaw, with no user interaction required, causing the service to overflow a heap buffer. Successful exploitation grants a high-impact elevation of privilege, with full confidentiality, integrity, and availability impact on the host, effectively handing the attacker far greater rights than they started with. Any Windows system shipping the Biometric Service is in scope, though the source data does not specify which Windows builds or versions are affected. There is currently no known exploitation: the flaw is not in CISA KEV, no public proof-of-concept exists, and EPSS estimates only a ~0.2% chance of exploitation in the next 30 days.

What to do: Apply the Microsoft Windows security update that addresses CVE-2026-73015 as soon as it is released, and check Microsoft's advisory for the exact affected builds since they are not enumerated in the available data. Prioritize shared or multi-user endpoints, and especially machines where Windows Hello / biometric sign-in is enabled, since that is where the vulnerable service is actively exercised. Given no known exploitation, no public PoC, and low EPSS (~0.2%), treating this within the normal patch cycle is reasonable absent further threat intelligence.

Affected
Microsoft Windows Biometric Service (Windows operating system)
Estimated exposure
masson the order of 1 billion+ Windows devices (the Biometric Service ships as a default Windows component) — The Windows installed base is roughly 1.4 billion devices and the Biometric Service is present by default on modern Windows releases, so exposure plausibly tracks the full Windows fleet, though only machines with local accounts and ideally…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.