Junglewise Threat Intelligence

CVE-2026-78447: Microsoft Windows Biometric Service heap buffer overflow

CVE-2026-78447 · Severity: high · CVSS 7.8 · Published 2026-09-08

Executive brief

Windows Biometric Service is a system component that manages fingerprint and other biometric authentication on Windows devices. A heap-based buffer overflow in this service could allow an authenticated attacker with local access to execute arbitrary code and gain elevated system privileges, potentially compromising the entire device.

Technical details

A heap-based buffer overflow exists in the Windows Biometric Service due to improper bounds checking when processing biometric input or configuration data. The vulnerability requires local access and an authenticated user context to exploit. A successful attack allows an attacker to overwrite heap memory and execute arbitrary code with elevated privileges, effectively achieving privilege escalation. The specific attack vector and vulnerable code path details would be contained in the full Microsoft Security Update Guide.

Affected products

  • Microsoft Windows Biometric Service <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats