CVE-2026-73026
massLocal Privilege Escalation via Heap Overflow in Microsoft Windows Biometric Service
CVE-2026-73026 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, the Windows component that handles fingerprint and face sign-in. A local attacker who already holds a low-privileged account can trigger the flaw by sending malformed input to the service, without any user interaction. Successful exploitation lets the attacker elevate privileges on the local machine, typically gaining the rights needed to install software, change system settings, and access data of more privileged accounts. Any Windows edition that ships the Windows Biometric Service is potentially affected, with risk concentrated on machines where biometric sign-in (Windows Hello) is configured. Exploitation status is currently quiet: there is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.2% probability of exploitation within 30 days.
What to do: Apply Microsoft's security update for the affected Windows versions as soon as it is released via Windows Update, WSUS, or your patch management system. Because exploitation requires local low-privileged access, this can be handled in the routine patching cycle, but prioritize systems exposed to untrusted local logons (kiosks, shared workstations, RDS hosts) and machines with Windows Hello biometric sign-in enabled. No workaround is documented; verify after patching that the WBS update is installed on all Windows endpoints and servers in inventory.
| Microsoft Windows Biometric Service (Windows client and server editions) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.