Impact
An integer overflow or wraparound exists in the Windows Biometric Service that enables an authorized local attacker to gain elevated privileges. The flaw allows the attacker to manipulate internal calculations during biometric credential handling, potentially causing the service to execute code with SYSTEM-level privileges. This results in a loss of confidentiality and integrity for the compromised machine, and can be leveraged to compromise connected systems.
Affected Systems
Affected products include Microsoft Windows 10 versions 1607, 1809, 21H2 and 22H2, Microsoft Windows 11 versions 23H2, 24H2, 25H2 and 26H1, and Microsoft Windows Server 2016 (including Server Core), Windows Server 2019 (including Server Core), Windows Server 2022, and Windows Server 2025 (including Server Core).
Risk and Exploitability
The CVSS base score of 7.8 indicates a high severity of the vulnerability. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The exploitation requires a local, authorized user context, implying the attacker must have a user account that can invoke the biometric service. Once exploited, the attacker can assume SYSTEM privileges, creating a high-impact scenario for local compromise. Given the lack of public exploit data, the current risk relies mainly on the high severity and the likelihood that local users could execute the flawed service.
OpenCVE Enrichment