CVE-2026-69352: Windows Biometric Service Elevation of Privilege Vulnerability
Published Sep 8, 2026
·Updated
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
Other sources
Windows Biometric Service Elevation of Privilege Vulnerability
— Microsoft
Affected Software
1 affected component
Microsoft Windows Biometric Service
Event History
Sep 8, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeakness
CVE Published
via MITRE·05:17 PM
Data Sourced
via MITRE·05:17 PM
DescriptionSeverity
Data Sourced
via NVD·06:18 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this vulnerability?
An attacker must already be authorized on the affected Windows system and able to execute locally. The provided data does not indicate that remote exploitation or user interaction is required.
2
What is the likely impact of successful exploitation?
Successful exploitation can elevate the attacker's privileges locally. The supplied severity vector indicates high impacts to confidentiality, integrity, and availability.
3
Is there evidence that exploitation is occurring or that a fix is available?
The provided data rates exploitation as unknown and remediation level as official. It does not provide details about active exploitation, affected versions, patches, or mitigations.