Impact
The vulnerability is an integer overflow or wraparound in the Windows Biometric Service that allows an authorized local user to gain elevated privileges. The flaw arises from improper input validation when processing biometric authentication data. Exploiting the flaw can let a non‑administrator user inject crafted data that causes the service to overflow a counter or buffer, resulting in a change of execution context with elevated privileges. The impact is a local privilege escalation that may compromise confidentiality, integrity, or availability of the affected system.
Affected Systems
Affected operating systems include Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Microsoft Windows Server versions 2016 (standard and Server Core), 2019 (standard and Server Core), 2022, and 2025 (standard and Server Core). These systems include the default Windows Biometric Service component.
Risk and Exploitability
The CVSS score of 7.8 indicates moderate to high severity. EPSS data is unavailable, so the current likelihood of exploitation cannot be quantified. The vulnerability is not listed in CISA’s KEV catalog. Attackers need local access and permission to interact with the biometric service, so the attack vector is local. Once the integer overflow is triggered, the attacker can gain higher privileges typically to administrator level on the host.
OpenCVE Enrichment