Junglewise Threat Intelligence

CVE-2026-69773: Microsoft Windows Biometric Service heap buffer overflow

CVE-2026-69773 · Severity: high · CVSS 8 · Published 2026-09-08

Technologies: Microsoft Windows Biometric Service. Vendors: Microsoft.

Executive brief

Windows Biometric Service is a core Windows component that manages fingerprint and facial recognition authentication. A heap buffer overflow vulnerability allows an authorized attacker to execute code with elevated privileges across the network, potentially compromising system security and enabling unauthorized access to the machine and its data.

Technical details

A heap-based buffer overflow exists in the Windows Biometric Service that can be triggered by an authorized network attacker. The vulnerability allows an attacker to write data beyond allocated buffer boundaries in the heap, enabling arbitrary code execution with elevated privileges. The attack requires prior authentication and network access to the affected system. Successful exploitation leads to privilege escalation, allowing an attacker to gain SYSTEM-level access. Microsoft has released security updates to patch this vulnerability.

Affected products

  • Microsoft Windows Biometric Service

Timeline

  • 2026-09-08: disclosed

References

Related threats