CVE-2026-73007
Executive Summary
CVE-2026-73007: A heap-based buffer overflow in Windows Biometric Service permits an authorized local user to gain elevated privileges. The flaw can be exploited by a user with access to the biometric service, potentially allowing execution of arbitrary code with higher privileges. No current CISA KEV listing.
Authoritative CVE Metadata - CVSS Base Score: 7.8 (HIGH) - Published: 2026-09-08T18:20:29.487 - Last Modified: 2026-09-12T04:16:37.637
Original Description: Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
"To study and not think is a waste. To think and not study is dangerous."
— Confucius
Source: NVD