Impact
The Windows Biometric Service contains a heap-based buffer overflow that lets an attacker with prior local authorization gain higher privileges on the affected system. This type of flaw allows malicious code to overwrite memory on the heap, potentially leading to execution of arbitrary code with elevated rights, thereby compromising system integrity and confidentiality. The weakness is represented by CWE‑122 and CWE‑20, indicating a buffer overflow and insufficient input validation, respectively. The impact can include full system takeover if the attacker leverages the flaw after obtaining sufficient local credentials.
Affected Systems
The vulnerability affects Microsoft Windows 10 from build 1607 up to 22H2, Windows 11 from versions 23H2 through 26H1, and Windows Server 2016, 2019, 2022, and 2025, including Server Core installations. All listed builds are susceptible when the Windows Biometric Service is operational.
Risk and Exploitability
The CVSS score of 7.8 reflects moderate to high severity for local privilege escalation. EPSS is not available, but the lack of prior exploitation reports and absence from the CISA KEV catalog suggest that mass exploitation is unlikely at present. The likely attack vector is a local, authenticated attacker who can interact with the Windows Biometric Service, such as a user capable of supplying biometric input. If the attacker successfully triggers the overflow, they can obtain system-level permissions, enabling full control of the affected machine.
OpenCVE Enrichment