Junglewise Threat Intelligence

CVE-2026-69298: Microsoft Windows Biometric Service integer overflow privilege escalation

CVE-2026-69298 · Severity: high · CVSS 7.8 · Published 2026-09-08

Technologies: Microsoft Windows Biometric Service. Vendors: Microsoft.

Executive brief

Windows Biometric Service is a Windows system component that manages fingerprint and other biometric authentication. An integer overflow flaw in this service allows an authorized local user to escalate their privileges to higher system levels, potentially gaining administrative access to the computer.

Technical details

An integer overflow or wraparound vulnerability exists in Microsoft Windows Biometric Service. The flaw is exploitable by an authenticated local attacker to achieve privilege escalation. The attack vector is local, requiring authentication and local system access. There is no indication of active exploitation in the wild at this time. Patches are expected from Microsoft Security Response Center.

Affected products

  • Microsoft Windows Biometric Service

Timeline

  • 2026-09-08: disclosed

References

Related threats