Executive brief
Windows Biometric Service is a system component that manages fingerprint and other biometric authentication on Windows devices. A heap buffer overflow in this service allows a user with local access to escalate their privileges to system-level, potentially compromising the entire device and any data stored on it.
Technical details
This vulnerability is a heap-based buffer overflow in the Windows Biometric Service that can be exploited by an authorized local user to achieve privilege escalation. The vulnerability requires local access and user authentication to trigger. Successful exploitation allows an attacker to execute arbitrary code with elevated system privileges. Microsoft has issued a security update to patch this vulnerability (CVE-2026-73011).
Affected products
- Microsoft Windows Biometric Service
Timeline
- 2026-09-08: disclosed