ZeroHour

CVE-2026-78447

mass

Heap Buffer Overflow in Windows Biometric Service Enables Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p15
Published
()
Modified
AI analysis

CVE-2026-78447 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, the component that handles Windows Hello fingerprint and facial-recognition sign-in. An attacker who already has low-privileged code execution on a local machine can trigger the flaw by sending crafted input to the service, with no user interaction required. Successful exploitation elevates the attacker's privileges locally, with high impact on confidentiality, integrity, and availability of the system. All in-scope Windows 10 and Windows 11 client releases (1607 through 26H1) and Windows Server 2016 through 2025 are affected, since the Biometric Service ships with these versions by default. Exploitation has not been observed: there is no known in-the-wild use, no public proof-of-concept, it is not in CISA KEV, and EPSS is low at 0.2%.

What to do: Apply the Microsoft security update addressing CVE-2026-78447 to all in-scope Windows 10, Windows 11, and Windows Server systems as soon as it is available through Windows Update, WSUS, or Intune. Prioritize endpoints and servers where untrusted or low-privileged users can run code, such as shared workstations, kiosks, VDI hosts, and RDS servers. As an interim mitigation, systems that do not use Windows Hello biometric sign-in can have the Windows Biometric Service disabled to shrink the attack surface.

Affected
microsoft Windows 101607, 1809, 21H2, 22H2
microsoft Windows 1123H2, 24H2, 25H2, 26H1
microsoft Windows Server2016, 2019, 2022, 2025
Estimated exposure
masshundreds of millions of Windows endpoints and servers across the affected versions — The Windows Biometric Service is present by default on the in-scope Windows 10/11 client releases and Windows Server versions, whose combined installed base is in the hundreds of millions of devices, though actual exploitability requires…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.