Junglewise Threat Intelligence

CVE-2026-72993: Microsoft Windows Biometric Service heap buffer overflow

CVE-2026-72993 · Severity: high · CVSS 7.8 · Published 2026-09-08

Executive brief

Windows Biometric Service is a core Windows component that processes biometric authentication data such as fingerprints and facial recognition. A heap buffer overflow vulnerability allows an authenticated attacker to execute code with elevated privileges on a system, potentially gaining full administrative control.

Technical details

A heap-based buffer overflow exists in the Windows Biometric Service (WbioSvc) that can be triggered by an authenticated local attacker. The vulnerability stems from improper bounds checking when processing biometric input data. Since the attack requires prior authentication/authorization on the system and is local in nature, network-based exploitation is not possible. A successful exploit allows privilege escalation from a standard user to SYSTEM-level access. A patch from Microsoft is expected on the regular security update cycle.

Affected products

  • Microsoft Windows

Timeline

  • 2026-09-08: disclosed
  • 2026-09-08: advisory: CVE-2026-72993 published on NVD and MSRC

References

Related threats