Junglewise Threat Intelligence

CVE-2026-69293: Microsoft Windows heap-based buffer overflow in Biometric Service

CVE-2026-69293 · Severity: high · CVSS 7.8 · Published 2026-09-08

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

Windows Biometric Service is a core component of Windows that handles fingerprint, facial recognition, and other biometric authentication. A heap-based buffer overflow vulnerability allows an authorized local user to run malicious code with system privileges, potentially gaining complete control of the affected computer and accessing all data stored on it.

Technical details

A heap-based buffer overflow exists in Windows Biometric Service that can be exploited by an authenticated local attacker to corrupt memory and execute arbitrary code with elevated privileges. The vulnerability requires the attacker to already have a user account on the system. Once triggered, the buffer overflow can be leveraged to bypass security protections and achieve privilege escalation from standard user to SYSTEM level. A patch is expected to be available through Windows Update.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats