Impact
The flaw is a heap-based buffer overflow in Windows Biometric Service that permits an authorized local user to elevate privileges. The overflow occurs when the service processes specially crafted biometric data, allowing the attacker to raise their privileges without bypassing authentication. This vulnerability is identified as CWE-122.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2 and 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, 26H1; Microsoft Windows Server 2016, 2019, 2022 and 2025, including Server Core installations.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local; an attacker must be authenticated or otherwise authorized on the affected machine to abuse the buffer overflow and raise privileges.
OpenCVE Enrichment