Impact
A heap-based buffer overflow in the Windows Biometric Service allows an attacker who is already authenticated to the system to obtain higher privileges locally. This flaw could enable the attacker to execute arbitrary code with elevated rights and potentially compromise the entire operating system or the host network. The weakness is identified as CWE-122, indicating that improper handling of heap memory can corrupt execution flow.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Windows Server 2016 (including Server Core), 2019 (including Server Core), 2022, and 2025 (including Server Core).
Risk and Exploitability
The CVSS score of 7.8 classifies this vulnerability as high severity, yet the EPSS score is currently not available, suggesting that exploitation data is limited. The vulnerability is not listed in the CISA KEV catalog, implying there are no confirmed exploits in the wild yet. However, because the attack requires local authorization and a heap overflow in a core system service, a skilled attacker could easily craft and deploy a local payload, making the risk significant for environments where users possess administrative or elevated rights.
OpenCVE Enrichment