Impact
A heap‑based buffer overflow in the Windows Biometric Service allows an attacker who already has local access to elevate privileges. The flaw originates from improper handling of memory allocations, enabling a crafted request to corrupt critical data structures and gain higher access rights. The vulnerability is classified as CWE‑122 and CWE‑190.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; Windows Server 2016, 2019, 2022, 2025. All builds listed above are affected.
Risk and Exploitability
The CVSS v3.1 score is 7.8, indicating high severity. EPSS data is not available, and the issue is not listed in CISA KEV, suggesting no confirmed widespread exploitation. However, because the attack requires local, authorized access, the threat remains significant in environments where privileged accounts are shared or where the Windows Biometric Service is enabled.
OpenCVE Enrichment