Junglewise Threat Intelligence

CVE-2026-72992: Microsoft Windows Biometric Service heap-based buffer overflow

CVE-2026-72992 · Severity: high · CVSS 7.8 · Published 2026-09-08

Executive brief

Windows Biometric Service is a core Windows system component that handles fingerprint and other biometric authentication on client devices. A heap buffer overflow vulnerability allows an authenticated local user to execute code with elevated system privileges, potentially leading to complete compromise of the affected device.

Technical details

A heap-based buffer overflow exists in the Windows Biometric Service that fails to properly validate input when processing biometric data, allowing an attacker with local access and valid authentication credentials to trigger memory corruption. The vulnerability resides in core biometric processing logic and requires prior authentication but no user interaction for exploitation. A successful exploit permits an attacker to achieve arbitrary code execution in the context of the system service, enabling privilege escalation from an authenticated user to NT AUTHORITY\SYSTEM. Microsoft has released security updates to address this vulnerability.

Affected products

  • Microsoft Windows Biometric Service <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats