Junglewise Threat Intelligence

CVE-2026-69727: Microsoft Windows Biometric Service heap buffer overflow

CVE-2026-69727 · Severity: high · CVSS 8 · Published 2026-09-08

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

Windows Biometric Service is a core Windows component that manages biometric authentication data. A heap-based buffer overflow in this service allows an attacker with network access and valid credentials to crash the service or execute arbitrary code, potentially gaining elevated privileges on the system.

Technical details

A heap-based buffer overflow vulnerability exists in the Windows Biometric Service due to insufficient bounds checking when processing biometric data. An authenticated attacker with network access can send a specially crafted request to trigger the overflow, corrupting heap memory and potentially achieving remote code execution with elevated privileges. The vulnerability requires the attacker to be authenticated and have network connectivity to the target system.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats