CVE-2026-73007

Executive Summary

CVE-2026-73007: A heap-based buffer overflow in Windows Biometric Service permits an authorized local user to gain elevated privileges. The flaw can be exploited by a user with access to the biometric service, potentially allowing execution of arbitrary code with higher privileges. No current CISA KEV listing.


Authoritative CVE Metadata - CVSS Base Score: 7.8 (HIGH) - Published: 2026-09-08T18:20:29.487 - Last Modified: 2026-09-12T04:16:37.637

Original Description: Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

"To study and not think is a waste. To think and not study is dangerous."

— Confucius
Source: NVD