ZeroHour

CVE-2026-77489

mass

Local Privilege Escalation via Null Pointer Dereference in Windows Biometric Service

CVSS 3.1
7.8 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-77489 is a null pointer dereference (CWE-476) in the Windows Biometric Service, the Windows component that handles fingerprint, facial, and other biometric authentication. An authorized attacker — i.e., someone who already has a low-privileged account on the machine — can trigger the flaw, most likely by getting the service to process malformed input or a crafted request that causes it to dereference a null pointer. Successful exploitation lets the attacker elevate privileges locally on the host, with the CVSS vector rating impact high across confidentiality, integrity, and availability (CVSS 3.1 score 7.8, AV:L/PR:L/UI:N). Any Windows installation running the Biometric Service is potentially affected, although this record does not specify which Windows editions or version ranges are impacted. There is currently no known exploitation: no public proof-of-concept, not listed in CISA KEV, and a low EPSS of 0.3% (25th percentile).

What to do: Apply the fix through Microsoft's monthly cumulative Windows updates as soon as your patch channel delivers it, prioritizing systems where untrusted users can execute code locally (multi-user servers, kiosks, shared or RDP-exposed workstations). Because this record omits affected version ranges, verify applicability against Microsoft's advisory for CVE-2026-77489 before and after patching. As an interim mitigation, restrict local and remote (RDP) logon to trusted accounts and watch for crashes of the Biometric Service (WbioSrvc) that could indicate probing.

Affected
Microsoft Windows Biometric Service (Windows)
Estimated exposure
masshundreds of millions of Windows installations (Biometric Service is a default Windows client component) — The Biometric Service ships by default with Windows client editions, and Windows' active installed base is publicly estimated at well over a billion devices, so plausible exposure is on the order of hundreds of millions of endpoints,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Null pointer dereference in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-476
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.