Impact
A heap-based buffer overflow in the Windows Biometric Service allows a user who can already log on to an affected system to supply crafted input that overflows a heap buffer, leading to execution of arbitrary code in the context of the service. Because the service runs with SYSTEM privileges, the attacker can acquire full control of the local machine, install malware, modify system files, or move laterally within the network. The flaw arises from improper input validation and is classified under CWE‑122 and CWE‑20.
Affected Systems
Microsoft Windows 10 (versions 1607, 1809, 21H2, 22H2) and Windows 11 (versions 23H2, 24H2, 25H2, 26H1) as well as Microsoft Windows Server 2016 (including Server Core), 2019 (including Server Core), 2022, and 2025 (including Server Core) are affected.
Risk and Exploitability
The CVSS score of 7.8 classifies this as a high-severity local privilege escalation. EPSS data is not available, so the current exploitation probability cannot be quantified, but the flaw is not listed in CISA’s KEV catalog, indicating no known widespread exploitation. Attackers would need local access with user privileges and crafted input to trigger the overflow. In environments where the biometric service is critical, the risk remains significant until mitigation is applied.
OpenCVE Enrichment