Junglewise Threat Intelligence

CVE-2026-73002: Microsoft Windows Biometric Service integer overflow privilege escalation

CVE-2026-73002 · Severity: high · CVSS 7.8 · Published 2026-09-08

Executive brief

Windows Biometric Service is a system component that manages fingerprint and facial recognition authentication on Windows devices. An authorized attacker with local access can exploit an integer overflow vulnerability to gain elevated administrative privileges, potentially compromising the entire system and bypassing security controls.

Technical details

An integer overflow or wraparound vulnerability exists in the Windows Biometric Service that allows an authenticated local attacker to achieve privilege escalation. The vulnerability is reachable only by users with local access to the system. Exploitation enables an attacker with valid credentials to elevate privileges and gain system-level access. No patch availability information is provided in the advisory; consult Microsoft Security Response Center for remediation guidance.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats