CVE-2026-78448
massHeap-Based Buffer Overflow in Windows Biometric Service Allows Local Privilege Escalation
CVE-2026-78448 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, a component of Microsoft Windows. An authorized (already authenticated) local attacker can trigger the flaw by interacting with the service, corrupting heap memory in the process. Successful exploitation elevates the attacker's privileges on the local machine, with high impact on confidentiality, integrity, and availability per the CVSS score of 7.8. Any Windows system running the Biometric Service is in scope, though the specific affected version ranges are not enumerated in the available data. Exploitation status is currently quiet: there is no known public proof of concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.2% chance of exploitation in the next 30 days.
What to do: Apply Microsoft's security update for this CVE when it is released, and check the Microsoft advisory for the exact affected Windows builds. Prioritize patching endpoints where Windows Hello biometric sign-in is enabled and systems that allow sign-in by low-privileged or shared local users, since an authorized local user is the required starting point. No public PoC or in-the-wild exploitation is known at this time, so there are no interim mitigations beyond the update.
| Microsoft Windows Biometric Service (Microsoft Windows) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.