Impact
Heap-based buffer overflow in the Windows Biometric Service allows an authorized local user to elevate privileges to a higher level. This overflow can lead to arbitrary code execution or privilege escalation within the same user context, potentially granting the attacker access to protected resources, system configuration changes, or malware installation. The vulnerability involves a heap overflow (CWE-122) and improper input validation (CWE-20).
Affected Systems
The flaw impacts various Microsoft Windows releases, including Windows 10 from version 1607 through 22H2, Windows 11 versions 23H2 to 26H1, and Windows Server 2016, 2019, 2022, and 2025 in both standard and Server Core installations. All affected systems contain the Windows Biometric Service and remain vulnerable unless patched.
Risk and Exploitability
The CVSS score of 7.8 classifies this issue as high severity. EPSS data is not currently available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is local; an attacker must already have access to the machine or install malicious code to trigger the heap overflow. Once exploited, privilege escalation could compromise the entire local environment. Therefore, prompt patching is essential to mitigate the risk, especially on systems with sensitive data or critical services.
OpenCVE Enrichment