Impact
Heap‑based buffer overflow in the Windows Biometric Service allows an attacker who has local authorized access to elevate privileges. The overflow can be triggered by supplying crafted input to the service, leading to execution of arbitrary code with higher privileges. This flaw, classified as CWE‑122, can compromise system confidentiality, integrity and availability if exploited.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, 26H1; Microsoft Windows Server 2016, 2019, 2022, 2025 (including server core installations).
Risk and Exploitability
The CVSS score of 7.8 assigns this flaw a medium‑high severity. No EPSS score is provided, and the vulnerability is not listed in the CISA KEV catalog, indicating no confirmed widespread exploitation. The presumption is that an attacker requires local authorized credentials to exploit the overflow, making the attack vector local. Given the severity and local nature, organizations should treat this as a high‑risk issue until patched.
OpenCVE Enrichment