Impact
A heap-based buffer overflow in the Windows Biometric Service allows an attacker who already has local access to the machine to elevate their privileges. This vulnerability is classified under CWE-122. The impact is the ability to gain higher privileges from an authorized user context, potentially enabling activities such as installing malware, viewing confidential data, or modifying system settings without user consent.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Microsoft Windows Server releases 2016, 2019, 2022, and 2025, including both full and Server Core installations. These platforms are impacted because the Biometric Service runs with elevated rights on each of these releases and includes the vulnerable code path.
Risk and Exploitability
The vulnerability has a CVSS score of 7.8, indicating a high severity level. No EPSS score is available, and it is not listed in the CISA KEV catalog, suggesting that it is not yet widely exploited in the wild. The likely attack vector is local: an attacker must first obtain some level of access to the target system, for example by compromising a user account or using another local exploit. Once the attacker is able to send malformed biometric data to the service, the buffer overflow can be triggered to achieve privilege escalation.
OpenCVE Enrichment