ZeroHour

CVE-2026-78448

mass

Heap-Based Buffer Overflow in Windows Biometric Service Allows Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p16
Published
()
Modified
AI analysis

CVE-2026-78448 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, a component of Microsoft Windows. An authorized (already authenticated) local attacker can trigger the flaw by interacting with the service, corrupting heap memory in the process. Successful exploitation elevates the attacker's privileges on the local machine, with high impact on confidentiality, integrity, and availability per the CVSS score of 7.8. Any Windows system running the Biometric Service is in scope, though the specific affected version ranges are not enumerated in the available data. Exploitation status is currently quiet: there is no known public proof of concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.2% chance of exploitation in the next 30 days.

What to do: Apply Microsoft's security update for this CVE when it is released, and check the Microsoft advisory for the exact affected Windows builds. Prioritize patching endpoints where Windows Hello biometric sign-in is enabled and systems that allow sign-in by low-privileged or shared local users, since an authorized local user is the required starting point. No public PoC or in-the-wild exploitation is known at this time, so there are no interim mitigations beyond the update.

Affected
Microsoft Windows Biometric Service (Microsoft Windows)
Estimated exposure
masshundreds of millions of Windows devices (Biometric Service is a standard component of Windows client editions) — Windows runs on the majority of the world's desktop and laptop fleets and ships the Biometric Service by default, so the population of potentially affected endpoints is on the order of hundreds of millions of devices, though exploitation…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.