Junglewise Threat Intelligence

CVE-2026-69323: Microsoft Windows Biometric Service heap buffer overflow

CVE-2026-69323 · Severity: high · CVSS 7.8 · Published 2026-09-08

Technologies: Microsoft Windows Biometric Service. Vendors: Microsoft.

Executive brief

Windows Biometric Service is a system component that processes fingerprint and other biometric authentication data on Windows systems. A heap buffer overflow vulnerability in this service allows an authorized user on the system to craft malicious input that crashes the service or executes arbitrary code with elevated privileges, potentially compromising system security and user data.

Technical details

A heap-based buffer overflow exists in the Windows Biometric Service, allowing an authenticated local attacker to overwrite heap memory and gain privilege escalation. The vulnerability requires an authenticated attacker with local access to the system; it is not remotely exploitable. An attacker can supply specially crafted input to trigger the overflow and execute arbitrary code with elevated privileges. A fix is available via Windows security updates from Microsoft.

Affected products

  • Microsoft Windows Biometric Service

Timeline

  • 2026-09-08: disclosed

References

Related threats