Impact
An integer overflow or wraparound in the Windows Biometric Service allows an authorized user who already has access to a target system to elevate their privileges locally. The flaw enables the attacker to bypass security checks and gain higher integrity levels, potentially allowing them to execute arbitrary code or gain full control over the affected machine.
Affected Systems
Affected systems include Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1, and 23H2; and Microsoft Windows Server editions 2016, 2019, 2022, and 2025, in both normal and Server Core configurations.
Risk and Exploitability
The vulnerability has a CVSS score of 7.8, indicating a high severity. Exploitability is limited to local contexts where the attacker already has access to the system and privileges sufficient to run the biometric service. EPSS data are not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that it has not yet been widely observed in the wild, but the local nature and high severity remain a concern for target systems.
OpenCVE Enrichment