Impact
A heap-based buffer overflow exists in the Windows Biometric Service. When triggered, the overflow allows an authorized local attacker to gain higher privileges on the affected Windows system. The weakness is characterized by overflows and integer miscalculations, as identified by CWE-122 and CWE-190. The resulting impact is that a user who can access the biometric interfaces could potentially execute privileged code on the host.
Affected Systems
Microsoft products affected include Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; and Windows Server 2016, 2019, 2022, and 2025, both full and core installations. These encompass a broad range of desktop and server releases across both x86 and x64 architectures.
Risk and Exploitability
The CVSS score is 7.8, which places the vulnerability in the High severity range. EPSS data is not available, and the issue is not listed in CISA’s KEV catalog, indicating no known widespread exploitation at the time of the assessment. The attack path requires local system access and an authenticated user with permissions to interact with the biometric service. Given the local nature of the vulnerability, the exploitation likelihood is limited to users who can legitimately leverage biometric features but may exploit the service’s unbounded memory usage to gain elevated privileges.
OpenCVE Enrichment