Impact
The vulnerability is a heap-based buffer overflow in the Windows Biometric Service that enables an authorized local attacker to gain elevated privileges on the affected machine. Exploitation could allow the attacker to run code with higher privileges, potentially compromising system integrity, confidentiality, and the ability to surreptitiously modify or install software. The flaw is identified as CWE-122.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, 26H1 (including 23H2 duplicates); Microsoft Windows Server 2016 (regular and Server Core), 2019 (regular and Server Core), 2022, and 2025 (regular and Server Core). These editions are listed as vulnerable and are identified by the corresponding Windows OS product names.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity; the EPSS score is not available, so the precise likelihood of exploitation cannot be quantified. The vulnerability is listed as not yet included in the CISA KEV catalog, which suggests that there is no known widespread exploitation at the time of this analysis. The attack vector is local, meaning that an attacker must have physical or otherwise authorized access to the target system to trigger the overflow and gain elevated rights.
OpenCVE Enrichment