CVE-2026-73026 Windows Biometric Service Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-73026 US
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-73026 US
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-73007 US
Heap-based buffer overflow in Windows Services for NFS ONCRPC XDR Driver allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-73024 US
Use after free in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-73005 US
Exposure of private personal information to an unauthorized actor in Windows Biometric Service allows an authorized attacker to disclose information locally.
EPSS 0.00 CVE-2026-73008 US
Missing authorization in Data Sharing Service Client allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-73014 US
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-73011 US
Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-73022 US
Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-73003 US
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-73015 US
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-73021 US
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-73001 US
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-73000 US
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-73020 US
Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-73002 US
Out-of-bounds read in Windows USB Hub Driver allows an unauthorized attacker to elevate privileges with a physical attack.
EPSS 0.00 CVE-2026-72999 US
Improper resolution of path equivalence in Windows URL Moniker allows an unauthorized attacker to bypass a security feature over a network.
EPSS 0.01 CVE-2026-73019 US
Heap-based buffer overflow in Graphic Fonts allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-73018 US
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-72997 US
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-72996 US
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-72994 US
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-72993 US
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-72992 US
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-72991 US
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-72990 US
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-72988 US
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-72995 US
Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-72987 US
Use of uninitialized resource in Windows Failover Cluster allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-72989 US
Improper handling of highly compressed data (data amplification) in ASP.NET Core allows an unauthorized attacker to deny service over a network.
EPSS 0.01 CVE-2026-69304 US
Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69465 Microsoft US
Insertion of sensitive information into sent data in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.
EPSS 0.00 CVE-2026-65812 Microsoft US
Deserialization of untrusted data in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-65772 Microsoft US
Heap-based buffer overflow in Windows Volume Shadow Copy allows an unauthorized attacker to elevate privileges with a physical attack.
EPSS 0.00 CVE-2026-72985 US
Out-of-bounds read in Microsoft Office Word allows an authorized attacker to disclose information locally.
EPSS 0.00 CVE-2026-72976 Microsoft US
Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-72975 Microsoft US
Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-72977 Microsoft US
Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-72974 Microsoft US
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-72973 Microsoft US
Access of resource using incompatible type ('type confusion') in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-72938 Microsoft US
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-72972 Microsoft US
Untrusted pointer dereference in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-72956 Microsoft US
Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine
EPSS 0.00 CVE-2026-70570 US
Out-of-bounds write in Windows Imaging Component allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-70296 US
Heap-based buffer overflow in Windows Media Player allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-70203 US
Heap-based buffer overflow in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-69906 US
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-69904 Microsoft US
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Installer allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-69441 US
Origin validation error in .NET allows an unauthorized attacker to disclose information over a network.
EPSS 0.00 CVE-2026-58649 US
External control of file name or path in .NET allows an unauthorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-69805 US
Heap-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-69439 US
Use after free in Microsoft Office allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69632 Microsoft US
Buffer over-read in Microsoft Office allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-69626 Microsoft US
Heap-based buffer overflow in Microsoft Office Access allows an authorized attacker to execute code locally.
EPSS 0.00 CVE-2026-69477 Microsoft US
Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69629 Microsoft US
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-69636 Microsoft US
Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69614 Microsoft US
Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-69464 Microsoft US
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
EPSS 0.00 CVE-2026-69615 Microsoft US
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69442 Microsoft US