Junglewise Threat Intelligence

CVE-2026-70572: Microsoft Windows Biometric Service integer overflow privilege escalation

CVE-2026-70572 · Severity: high · CVSS 7.8 · Published 2026-09-08

Executive brief

Windows Biometric Service is a core Windows component that processes biometric authentication data such as fingerprints and facial recognition. An authorized local user can exploit an integer overflow vulnerability to bypass security restrictions and gain elevated system privileges, potentially allowing complete control of the affected computer.

Technical details

An integer overflow or wraparound vulnerability exists in the Windows Biometric Service, a local system component responsible for processing biometric authentication data. The vulnerability is exploitable by an authenticated local user without network access. A successful exploit allows privilege escalation from a standard user context to SYSTEM or administrator level. Patches are available from Microsoft; users should apply the latest security updates for their Windows version.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats