Impact
A heap-based buffer overflow in the Windows Biometric Service permits a local attacker with authorized access to raise their privileges on the affected system. The vulnerability, classified as CWE‑122 and CWE‑20, can allow the attacker to gain elevated rights that are normally restricted, potentially compromising confidentiality, integrity, and availability of system data on a local scope.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1; Microsoft Windows Server 2016 (including Server Core), 2019 (including Server Core), 2022, and 2025 (including Server Core).
Risk and Exploitability
The assessment scores a CVSS of 7.8, indicating high severity, while the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a local exploitation scenario where an authorized user or process can trigger the overflow to achieve privilege escalation. No network or remote components are required, but the attack requires the ability to execute code within the context of the Biometric Service.
OpenCVE Enrichment