CVE-2026-77489
massLocal Privilege Escalation via Null Pointer Dereference in Windows Biometric Service
CVE-2026-77489 is a null pointer dereference (CWE-476) in the Windows Biometric Service, the Windows component that handles fingerprint, facial, and other biometric authentication. An authorized attacker — i.e., someone who already has a low-privileged account on the machine — can trigger the flaw, most likely by getting the service to process malformed input or a crafted request that causes it to dereference a null pointer. Successful exploitation lets the attacker elevate privileges locally on the host, with the CVSS vector rating impact high across confidentiality, integrity, and availability (CVSS 3.1 score 7.8, AV:L/PR:L/UI:N). Any Windows installation running the Biometric Service is potentially affected, although this record does not specify which Windows editions or version ranges are impacted. There is currently no known exploitation: no public proof-of-concept, not listed in CISA KEV, and a low EPSS of 0.3% (25th percentile).
What to do: Apply the fix through Microsoft's monthly cumulative Windows updates as soon as your patch channel delivers it, prioritizing systems where untrusted users can execute code locally (multi-user servers, kiosks, shared or RDP-exposed workstations). Because this record omits affected version ranges, verify applicability against Microsoft's advisory for CVE-2026-77489 before and after patching. As an interim mitigation, restrict local and remote (RDP) logon to trusted accounts and watch for crashes of the Biometric Service (WbioSrvc) that could indicate probing.
| Microsoft Windows Biometric Service (Windows) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Null pointer dereference in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
- Weakness
- CWE-476
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.