Impact
A heap-based buffer overflow within the Windows Biometric Service enables an attacker with local privileges to write arbitrary data to memory, leading to a privilege escalation. This flaw contains the typical characteristics of CWE-122 and permits the elevation of an authorized user’s rights without the need for additional exploits.
Affected Systems
Affected versions include Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2, Windows 11 versions 23H2, 24H2, 25H2, 26H1, as well as Windows Server 2016, 2019, 2022, and 2025 in both standard and Server‑Core installations.
Risk and Exploitability
The CVSS score of 7.8 indicates a high‑severity vulnerability with a substantial impact on integrity and availability. Although no EPSS value is published, the lack of a KEV listing suggests the exploit is not yet widely known in the wild, yet local adversaries could still leverage it. Attackers must first authenticate locally; thus the likely attack vector is local privilege escalation by a user who can execute code on the system.
OpenCVE Enrichment