Impact
A heap-based buffer overflow exists in the Windows Biometric Service that an attacker can exploit to gain higher privileges on a machine that already has network access to the service. The flaw allows the attacker to overwrite critical memory structures when the service processes biometric data, enabling the escalation of privileges. The weakness is classified as CWE‑122.
Affected Systems
Microsoft Windows and Windows Server operating systems are affected, including Windows 10 from version 1607 through 22H2, Windows 11 from versions 23H2, 24H2, 25H2 and 26H1, and Windows Server 2016, 2019, 2022, 2025 and their Server Core installations.
Risk and Exploitability
The CVSS score of 8 indicates a high severity vulnerability. No EPSS score is available, and the vulnerability is not currently listed in the CISA KEV catalog. Exploitation appears to require an attacker with legitimate network access to the target machine; public exploits have not been documented. The risk stems from the potential to elevate local or remote privileges to system level, compromising the entire system.
OpenCVE Enrichment