Impact
Windows Biometric Service contains a heap-based buffer overflow that an attacker with local authorization can exploit to gain higher privileges. The flaw allows elevation of privilege on the affected system and can enable arbitrary code execution with elevated rights, compromising confidentiality, integrity, and availability. The weakness corresponds to the common heap overflow vulnerability (CWE‑122).
Affected Systems
Affected Windows operating systems include Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Windows Server editions 2016, 2019, 2022, and 2025, including both standard and Server Core installations. All 32‑bit, 64‑bit, and ARM64 variants of these releases are vulnerable.
Risk and Exploitability
The CVSS score of 7.8 classifies this as a high‑severity local privilege escalation. Because the attacker must have authorized local access, the realistic exploitability depends on the user’s privileges, and the EPSS data is missing, so the probability cannot be quantified. The flaw is not currently listed in the CISA KEV catalog, indicating no publicly known exploits. The likely attack vector is a local user executing crafted input that triggers the heap overflow in the biometric service.
OpenCVE Enrichment