Junglewise Threat Intelligence

CVE-2026-73011: Microsoft Windows Biometric Service heap buffer overflow

CVE-2026-73011 · Severity: high · CVSS 7.8 · Published 2026-09-08

Executive brief

Windows Biometric Service is a system component that manages fingerprint and other biometric authentication on Windows devices. A heap buffer overflow in this service allows a user with local access to escalate their privileges to system-level, potentially compromising the entire device and any data stored on it.

Technical details

This vulnerability is a heap-based buffer overflow in the Windows Biometric Service that can be exploited by an authorized local user to achieve privilege escalation. The vulnerability requires local access and user authentication to trigger. Successful exploitation allows an attacker to execute arbitrary code with elevated system privileges. Microsoft has issued a security update to patch this vulnerability (CVE-2026-73011).

Affected products

  • Microsoft Windows Biometric Service

Timeline

  • 2026-09-08: disclosed

References

Related threats