Impact
An integer overflow or wraparound, a form of CWE-190, occurs in the Windows Biometric Service, allowing an attacker who has local authorized access to elevate privileges. The flaw enables the attacker to gain higher permissions than normally granted, potentially compromising system integrity and confidentiality.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; Windows Server 2016, 2019, 2022, 2025, including Server Core installations.
Risk and Exploitability
The advisory assigns a CVSS score of 7.8. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is local, requiring an authorized user context. The risk is moderate to high for systems that have not applied the patch, as the issue permits privilege escalation without remote exploitation.
OpenCVE Enrichment