Junglewise Threat Intelligence

CVE-2026-69352: Microsoft Windows Biometric Service heap buffer overflow

CVE-2026-69352 · Severity: high · CVSS 7.8 · Published 2026-09-08

Technologies: Microsoft Windows Biometric Service. Vendors: Microsoft.

Executive brief

Windows Biometric Service is a core Windows component that manages fingerprint and other biometric authentication methods. A heap-based buffer overflow vulnerability allows an authenticated local user to execute arbitrary code with elevated system privileges, potentially leading to complete system compromise.

Technical details

A heap-based buffer overflow exists in the Windows Biometric Service, allowing an authorized local attacker to trigger a memory corruption condition. The vulnerability requires prior authentication and local network access to exploit. Successful exploitation grants the attacker SYSTEM-level privileges, enabling full system compromise including installing malware, modifying system files, and stealing sensitive data. Microsoft has released patches for this vulnerability.

Affected products

  • Microsoft Windows Biometric Service <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats