Junglewise Threat Intelligence

CVE-2026-73007: Microsoft Windows Biometric Service heap-based buffer overflow

CVE-2026-73007 · Severity: high · CVSS 7.8 · Published 2026-09-08

Executive brief

Windows Biometric Service is a system component that manages fingerprint and other biometric authentication on Windows devices. A heap-based buffer overflow in this service could allow an authorized user on a local machine to escalate their privileges to system level, gaining full control over the device and access to all stored data.

Technical details

A heap-based buffer overflow vulnerability exists in the Windows Biometric Service that can be triggered by an authenticated local attacker to achieve privilege escalation. The vulnerability requires local access and pre-existing authorization on the affected system. Successful exploitation allows an attacker to execute arbitrary code with SYSTEM privileges, bypassing normal access controls. A patch is expected to be available via Microsoft Security Updates.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats