CVE-2026-72996

Executive Summary

CVE-2026-72996: A heap-based buffer overflow in the Windows Biometric Service can be exploited by an authorized local user to gain elevated privileges. The flaw occurs during processing of biometric data, allowing memory corruption that leads to privilege escalation. No current CISA KEV listing.


Authoritative CVE Metadata - CVSS Base Score: 7.8 (HIGH) - Published: 2026-09-08T18:20:27.907 - Last Modified: 2026-09-12T04:16:37.237

Original Description: Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

"It is through science that we prove, but through intuition that we discover."

— Jules Poincare
Source: NVD