Impact
Heap-based buffer overflow in the Windows Biometric Service permits a locally authenticated user or process to gain higher privileges. The flaw occurs when the service incorrectly manages heap allocations, leading to out‑of‑bounds writes. Exploitation can advance an authorized attacker’s privileges to system or administrator level, compromising confidentiality, integrity, and availability on the host. The weakness is classified as CWE‑122, a classic heap overflow.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2 and 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1 and 23H2; Windows Server 2016, 2019, 2022 and 2025, including Server Core installations. All relevant editions and architectures listed in the CVE include x86, x86_64, arm64 variants where applicable.
Risk and Exploitability
CVSS score of 7.8 indicates a high severity with local privilege escalation. No EPSS score is available, and the issue is not yet cataloged in CISA’s KEV catalog, suggesting it may not have widespread exploitation yet. However, the capability to elevate privileges locally enables attackers to install malware, tamper with system files, or access sensitive data. The attack requires a locally authenticated user or privileged process, but once executed, the impact spans the entire system.
OpenCVE Enrichment