Junglewise Threat Intelligence

CVE-2026-73001: Microsoft Windows Biometric Service heap-based buffer overflow

CVE-2026-73001 · Severity: high · CVSS 7.8 · Published 2026-09-08

Executive brief

Windows Biometric Service is a system component that processes biometric authentication data. A heap-based buffer overflow vulnerability allows an authorized local user to execute arbitrary code and escalate their privileges on an affected system.

Technical details

A heap-based buffer overflow exists in Microsoft Windows Biometric Service that can be triggered by an authenticated local attacker. The vulnerability stems from insufficient bounds checking when processing biometric input, allowing memory corruption. The attack requires local system access and existing user privileges. Successful exploitation results in arbitrary code execution with elevated system privileges. Microsoft has released a patch to address this vulnerability.

Affected products

  • Microsoft Windows Biometric Service <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats