Impact
The vulnerability is a heap-based buffer overflow (CWE‑122) in the Windows Biometric Service that enables an attacker with local authorization to overwrite memory and gain elevated privileges. An attacker could run code with higher system rights, which may be used to install malware, modify system settings, or tamper with security controls. The vulnerability is limited to exploiting the Biometric Service component and does not directly affect network services or remote users.
Affected Systems
Affected systems include Microsoft Windows 10 variants such as 1607, 1809, 21H2, 22H2, and Windows 11 versions 23H2, 24H2, 25H2, 26H1, as well as Windows Server 2016, 2019, 2022, and 2025, both standard and Server Core installations.
Risk and Exploitability
The severity is high with a CVSS score of 7.8. EPSS data is unavailable, indicating no quantifiable public exploitation probability yet, and the vulnerability is not listed in the CISA KEV catalog. The exploit requires local authorization, so an attacker must already have access to the target machine. Once executed, the attacker can elevate privileges on the system, making this a serious risk for any environment where local users have elevated privileges or where sensitive data is accessible to local accounts.
OpenCVE Enrichment