Executive brief
Windows Biometric Service is a system component that handles fingerprint and other biometric authentication on Windows systems. A heap buffer overflow vulnerability allows an authorized local user to execute arbitrary code and gain elevated system privileges, compromising the security of the entire system.
Technical details
A heap-based buffer overflow exists in the Windows Biometric Service that can be exploited by an authenticated local attacker to achieve privilege escalation. The vulnerability requires the attacker to have local access and valid credentials to trigger the overflow condition in the biometric service. Upon successful exploitation, an attacker can gain SYSTEM-level privileges and execute arbitrary code with the highest level of access on the affected system. A patch has been released by Microsoft as part of their regular security updates for CVE-2026-69476.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed