Impact
The vulnerability is a heap‑based buffer overflow in the Windows Biometric Service. Exploitation of the overflow can allow an attacker with local access to elevate privileges to the service's execution context. The weakness corresponds to CWE-122 and would enable the attacker to run arbitrary code or modify system state with elevated permissions.
Affected Systems
Affected products include Microsoft Windows 10 versions 1607, 1809, 21H2 and 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2 and 26H1; and Microsoft Windows Server 2016, 2019, 2022, and 2025, including Server Core installations.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity vulnerability. EPSS data is unavailable and the issue is not listed in the CISA KEV catalog, suggesting no known widespread exploitation yet. Attackers would need local privileges to trigger the overflow, so the threat is primarily from insiders or compromised local accounts. Organizations with strong local access controls may reduce risk.
OpenCVE Enrichment