Junglewise Threat Intelligence

CVE-2026-70581: Microsoft Windows Biometric Service integer overflow privilege escalation

CVE-2026-70581 · Severity: high · CVSS 7.8 · Published 2026-09-08

Executive brief

Windows Biometric Service is a system component that handles fingerprint and other biometric authentication on Windows devices. An integer overflow vulnerability in this service allows an authenticated local attacker to escalate their privileges to system level, potentially gaining full control of the device.

Technical details

An integer overflow or wraparound vulnerability exists in the Windows Biometric Service that can be exploited by an authorized local attacker to achieve privilege escalation. The vulnerability is rooted in improper handling of numeric values in a critical code path within the biometric service. Exploitation requires local access and prior authentication to the system. A successful exploit allows an attacker to execute arbitrary code with elevated (SYSTEM) privileges, bypassing Windows security boundaries. Patches are available from Microsoft.

Affected products

  • Microsoft Windows

Timeline

  • 2026-09-08: disclosed

References

Related threats