Junglewise Threat Intelligence

CVE-2026-73020: Microsoft Windows Biometric Service heap buffer overflow

CVE-2026-73020 · Severity: high · CVSS 7.8 · Published 2026-09-08

Executive brief

The Windows Biometric Service is a core Windows component that manages fingerprint and other biometric authentication features used to secure user login and access control. A heap-based buffer overflow in this service allows an attacker with authorized local access to crash the system or run arbitrary code with elevated privileges, potentially bypassing security controls and compromising the entire machine.

Technical details

A heap-based buffer overflow vulnerability exists in the Windows Biometric Service that can be exploited by an authorized local attacker to elevate privileges. The vulnerability is triggered through improper memory management in the biometric processing component, allowing an attacker to overwrite heap memory and execute arbitrary code in the context of a privileged service process. This requires prior authentication or local system access, but does not require user interaction. Successful exploitation grants the attacker SYSTEM-level privileges on the affected machine.

Affected products

  • Microsoft Windows

Timeline

  • 2026-09-08: disclosed

References

Related threats