Impact
A heap‑based buffer overflow exists in the Windows Biometric Service that allows an attacker who is already authenticated on the system to elevate privileges to administrative levels. The flaw arises when the service processes biometric data and does not properly validate the size of heap buffers it writes to, enabling control over the stack or adjacent memory. Successful exploitation results in an attacker gaining full control over the affected machine, potentially compromising all data, modifying system settings, or deploying additional malware.
Affected Systems
Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; Windows Server 2016, 2019, 2022, and 2025, including Server Core installations; all supported x86, x64, arm64 builds as listed by Microsoft.
Risk and Exploitability
The public CVSS score of 7.8 reflects a high severity local attack path. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog, indicating no confirmed widespread exploitation yet. The likely attack vector is a local exploit requiring the attacker to run code on the victim machine, such as via drive‑by exploitation or malicious biometric data injection. Due to the local nature, the exploitation mitigates to environments where users have legitimate access, but the impact remains high once elevated.
OpenCVE Enrichment