CVE-2026-78448

Executive Summary

CVE-2026-78448 is a heap‑based buffer overflow in the Windows Biometric Service that permits an authorized local attacker to gain elevated privileges. The flaw can be exploited by users with legitimate access to the biometric subsystem, potentially allowing them to execute code with higher privileges on the affected system. The vulnerability is not currently listed in the CISA KEV database.


Authoritative CVE Metadata - CVSS Base Score: 7.8 (HIGH) - Published: 2026-09-08T18:20:42.800 - Last Modified: 2026-09-12T04:16:37.980

Original Description: Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

"Using the power of decision gives you the capacity to get past any excuse to change any and every part of your life in an instant."

— Tony Robbins
Source: NVD