CVE-2026-78447
massHeap Buffer Overflow in Windows Biometric Service Enables Local Privilege Escalation
CVE-2026-78447 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, the component that handles Windows Hello fingerprint and facial-recognition sign-in. An attacker who already has low-privileged code execution on a local machine can trigger the flaw by sending crafted input to the service, with no user interaction required. Successful exploitation elevates the attacker's privileges locally, with high impact on confidentiality, integrity, and availability of the system. All in-scope Windows 10 and Windows 11 client releases (1607 through 26H1) and Windows Server 2016 through 2025 are affected, since the Biometric Service ships with these versions by default. Exploitation has not been observed: there is no known in-the-wild use, no public proof-of-concept, it is not in CISA KEV, and EPSS is low at 0.2%.
What to do: Apply the Microsoft security update addressing CVE-2026-78447 to all in-scope Windows 10, Windows 11, and Windows Server systems as soon as it is available through Windows Update, WSUS, or Intune. Prioritize endpoints and servers where untrusted or low-privileged users can run code, such as shared workstations, kiosks, VDI hosts, and RDS servers. As an interim mitigation, systems that do not use Windows Hello biometric sign-in can have the Windows Biometric Service disabled to shrink the attack surface.
| microsoft Windows 10 | 1607, 1809, 21H2, 22H2 |
| microsoft Windows 11 | 23H2, 24H2, 25H2, 26H1 |
| microsoft Windows Server | 2016, 2019, 2022, 2025 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.