Junglewise Threat Intelligence

CVE-2026-72997: Microsoft Windows Biometric Service heap buffer overflow

CVE-2026-72997 · Severity: high · CVSS 7.8 · Published 2026-09-08

Executive brief

Windows Biometric Service is a core Windows component that manages fingerprint, facial, and iris recognition for user authentication. A heap buffer overflow vulnerability allows a logged-in user to execute arbitrary code and escalate their privileges to administrator level, potentially compromising system security and enabling unauthorized access to sensitive data.

Technical details

A heap-based buffer overflow exists in the Windows Biometric Service, a component responsible for processing biometric authentication data. The vulnerability can be exploited by an authenticated local attacker through a specially crafted request, allowing arbitrary code execution within the service's context and subsequent privilege escalation from user to system/SYSTEM level. The attack requires local access and prior authentication but no additional user interaction. Microsoft has issued a patch via its Security Update Guide; affected systems should apply available security updates immediately.

Affected products

  • Microsoft Windows Biometric Service <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats