Junglewise Threat Intelligence

CVE-2026-73026: Microsoft Windows Biometric Service heap buffer overflow

CVE-2026-73026 · Severity: high · CVSS 7.8 · Published 2026-09-08

Executive brief

Windows Biometric Service is a system component that processes fingerprint and other biometric authentication data. A heap buffer overflow vulnerability allows an authenticated local user to crash the service or execute arbitrary code with elevated privileges, potentially compromising system integrity and user data security.

Technical details

A heap-based buffer overflow exists in Windows Biometric Service due to insufficient input validation in biometric data processing. The vulnerability requires an authenticated user with local access to the system. An attacker can trigger the overflow by submitting maliciously crafted biometric input, leading to memory corruption and privilege escalation from user to system level. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats