Impact
A heap-based buffer overflow exists in Windows Biometric Service. The flaw enables an authorized network attacker to write beyond allocated heap memory, potentially corrupting critical data structures and allowing the attacker to elevate privileges to system or administrator level. This is a classic memory corruption weakness identified as CWE-122.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; Windows Server 2016, 2019, 2022, 2025 (including Server Core installations).
Risk and Exploitability
The CVSS score of 8.0 indicates a high severity vulnerability. EPSS is not available, so the current exploit probability is unknown. The vulnerability is not listed in the CISA KEV table, indicating no confirmed exploitation in the wild yet. The likely attack path involves an authenticated network user sending crafted biometric data to the service, triggering the overflow. The success of the exploit depends on the attacker’s ability to reach the biometric service over the network and the service’s configuration.
OpenCVE Enrichment