ZeroHour

CVE-2026-73026

mass

Local Privilege Escalation via Heap Overflow in Microsoft Windows Biometric Service

CVSS 3.1
7.8 high
EPSS
<1%p16
Published
()
Modified
AI analysis

CVE-2026-73026 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, the Windows component that handles fingerprint and face sign-in. A local attacker who already holds a low-privileged account can trigger the flaw by sending malformed input to the service, without any user interaction. Successful exploitation lets the attacker elevate privileges on the local machine, typically gaining the rights needed to install software, change system settings, and access data of more privileged accounts. Any Windows edition that ships the Windows Biometric Service is potentially affected, with risk concentrated on machines where biometric sign-in (Windows Hello) is configured. Exploitation status is currently quiet: there is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.2% probability of exploitation within 30 days.

What to do: Apply Microsoft's security update for the affected Windows versions as soon as it is released via Windows Update, WSUS, or your patch management system. Because exploitation requires local low-privileged access, this can be handled in the routine patching cycle, but prioritize systems exposed to untrusted local logons (kiosks, shared workstations, RDS hosts) and machines with Windows Hello biometric sign-in enabled. No workaround is documented; verify after patching that the WBS update is installed on all Windows endpoints and servers in inventory.

Affected
Microsoft Windows Biometric Service (Windows client and server editions)
Estimated exposure
masshundreds of millions of Windows endpoints (WBS ships with the Windows client installed base of >1 billion devices) — The Windows Biometric Service is a built-in component of modern Windows client and server editions, so the plausible exposure is on the order of the overall Windows installed base (publicly estimated above one billion devices), even though…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.