ZeroHour

CVE-2026-73021

mass

Windows Biometric Service Heap Overflow Enables Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p25
Published
()
Modified
AI analysis

Microsoft has disclosed a heap-based buffer overflow (CWE-122, preceded by improper input validation, CWE-20) in the Windows Biometric Service, the operating-system component that handles fingerprint and other biometric authentication. The flaw is triggered by malformed data processed by the service, and an attacker who already holds a low-privileged local account can exploit it without any user interaction. Successful exploitation allows the attacker to elevate privileges on the local machine, with high impact on confidentiality, integrity and availability — effectively broader control of the host. Any Windows deployment that includes the Biometric Service is affected; Microsoft (the assigned CNA) has published the advisory, though specific affected Windows build numbers are not included in the available data. There is currently no known public proof-of-concept, no CISA KEV listing, and EPSS estimates only a 0.3% probability of exploitation in the next 30 days, indicating low near-term exploitation risk.

What to do: Apply Microsoft's security update for the Windows Biometric Service via Windows Update as soon as it is available, and consult Microsoft's advisory for the specific affected and fixed builds (not listed in the source data). Because exploitation requires an existing low-privileged local session, prioritize multi-user workstations, jump servers, and VDI/shared environments where local accounts are common. No public PoC or KEV listing exists and EPSS is low, so standard patch cadence is reasonable for isolated single-user endpoints.

Affected
Microsoft Windows Biometric Service (WbioSvc) — Windows operating system component
Estimated exposure
mass≈1 billion Windows devices ship the Biometric Service as a default OS component — The Windows Biometric Service is present by default across Microsoft's Windows installed base, which exceeds a billion devices, though successful exploitation additionally requires an attacker to already hold a low-privileged local session…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-20, CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.