Junglewise Threat Intelligence

CVE-2026-69738: Microsoft Windows Biometric Service integer overflow privilege escalation

CVE-2026-69738 · Severity: high · CVSS 7.8 · Published 2026-09-08

Technologies: Microsoft Windows Biometric Service. Vendors: Microsoft.

Executive brief

Windows Biometric Service is a core Windows component that manages biometric authentication devices. An authorized local user can exploit an integer overflow vulnerability to escalate privileges and gain administrative access to the system.

Technical details

An integer overflow or wraparound vulnerability exists in the Windows Biometric Service, a privileged Windows system service. The vulnerability allows an authorized local attacker to trigger a memory corruption condition through specially crafted input, leading to local privilege escalation. The attack requires prior local authentication or system access, limiting the threat to users who already have a foothold on the target system. A successful exploit grants the attacker SYSTEM-level privileges. Microsoft has released a patch for this vulnerability via their normal security update process.

Affected products

  • Microsoft Windows Biometric Service

Timeline

  • 2026-09-08: disclosed

References

Related threats