Impact
A heap-based buffer overflow exists within the Windows Biometric Service. When the service processes specially crafted data supplied by a user, it writes past the end of a heap buffer, allowing arbitrary code execution with the service’s privileges. This flaw is a classic buffer overflow weakness (CWE‑122) and a typical input validation error (CWE‑20). An attacker who has already authenticated to the system can exploit the vulnerability to elevate local privileges, potentially leading to system-wide compromise.
Affected Systems
The vulnerability affects Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Microsoft Windows Server 2016, 2019, 2022, and 2025, each in both standard and Server Core deployments. All affected builds run the Windows Biometric Service, which is enabled by default on these operating systems.
Risk and Exploitability
The flaw carries a CVSS score of 7, indicating high impact when local privileges are required. EPSS data is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting that widespread exploitation has not yet been observed. The typical attack scenario requires an authorized user to supply crafted input to the Biometric Service while logged in; once exploited, the attacker can gain elevated local privileges, which could ultimately permit system-wide compromise. Patch deployment remains the primary mitigation.
OpenCVE Enrichment