Junglewise Threat Intelligence

CVE-2026-69583: Microsoft Windows Biometric Service heap buffer overflow

CVE-2026-69583 · Severity: high · CVSS 7.8 · Published 2026-09-08

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

Windows Biometric Service is a Microsoft system component that processes fingerprint and other biometric authentication on Windows devices. A heap buffer overflow in this service allows an authenticated attacker on the same system to bypass security restrictions and gain elevated administrative privileges, potentially compromising the entire device.

Technical details

A heap-based buffer overflow exists in the Windows Biometric Service that processes biometric data. The vulnerability requires local access and prior authentication on the system. An attacker with valid credentials can craft malicious biometric input that triggers the overflow, allowing arbitrary code execution with system privileges and leading to privilege escalation. This is classified as a local privilege escalation vulnerability with a CVSS score of 7.8.

Affected products

  • Microsoft Windows

Timeline

  • 2026-09-08: disclosed

References

Related threats