Junglewise Threat Intelligence

CVE-2026-72996: Microsoft Windows Biometric Service heap buffer overflow

CVE-2026-72996 · Severity: high · CVSS 7.8 · Published 2026-09-08

Executive brief

Windows Biometric Service is a core Windows component that processes fingerprint and facial recognition authentication. A heap buffer overflow in this service allows an authorized local user to crash the service or run arbitrary code with elevated privileges, potentially compromising system security and bypassing access controls.

Technical details

A heap-based buffer overflow exists in the Windows Biometric Service, triggered by improper input validation or bounds checking in memory allocation. The vulnerability requires local access and prior authentication to trigger, but allows an attacker to overwrite heap memory and potentially achieve arbitrary code execution or elevate privileges. Attack vector is local; remote exploitation is not feasible. A patch has been published by Microsoft addressing this issue.

Affected products

  • Microsoft Windows

Timeline

  • 2026-09-08: disclosed

References

Related threats