Junglewise Threat Intelligence

CVE-2026-72988: Microsoft Windows Biometric Service heap buffer overflow

CVE-2026-72988 · Severity: high · CVSS 7.8 · Published 2026-09-08

Executive brief

Windows Biometric Service, a component used for fingerprint and facial recognition authentication on Windows systems, contains a heap-based buffer overflow vulnerability. An attacker with local system access could exploit this flaw to escalate privileges and gain complete control of the affected computer.

Technical details

A heap-based buffer overflow vulnerability exists in the Windows Biometric Service, allowing an authenticated local attacker to overflow a heap buffer and achieve privilege escalation. The vulnerability requires local access and pre-existing credentials on the target system. An attacker exploiting this flaw can execute arbitrary code with elevated privileges, potentially gaining SYSTEM-level access. A patch has been released by Microsoft and should be applied through Windows Update.

Affected products

  • Microsoft Windows Biometric Service <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats