Impact
The vulnerability is a heap‑based buffer overflow in the Windows Biometric Service, allowing a local user with legitimate access to gain elevated privileges on the system. By overflowing the service’s buffer, an attacker can manipulate control flow and obtain higher-level rights, potentially enabling complete system compromise. The weakness is identified as CWE‑122 and the CVSS score of 7.8 denotes high severity.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1; Microsoft Windows Server 2016, 2019, 2022, and 2025, including all Server Core installation variants. The flaw resides in the built‑in Windows Biometric Service shipped with these operating systems.
Risk and Exploitability
The CVSS score of 7.8 reflects a significant risk to confidentiality, integrity, and availability for the affected systems. No EPSS score is available, and the issue is not currently listed in the CISA KEV catalog, indicating that no widespread exploitation has been observed yet. The likely attack vector is local; an authenticated user would need to execute a crafted payload that triggers the overflow within the biometric service, after which elevated privileges are granted. The lack of a remote entry point limits the threat to environments where an attacker can interact with the target machine directly or via physical access.
OpenCVE Enrichment