Impact
A buffer overflow can be triggered in the Windows Biometric Service, which runs in the Windows kernel. The flaw is a heap-based overflow that, when successfully exploited, allows a local, authorized attacker to gain higher privileges on the affected machine. The vulnerability is classified as CWE‑122, indicating a classic bounds‑overrun condition capable of corrupting control data or resulting in a crash. The impact is that an attacker who already has local access can elevate privileges, potentially gaining administrative rights and the ability to modify system files, install malware, or exfiltrate data. Because the overflow occurs in a privileged service, the level of compromise is high once the exploit is executed.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2, as well as Windows 11 releases 23H2, 24H2, 25H2, and 26H1 are affected, together with Windows Server 2016, 2019, 2022, and 2025, including Server Core installations. All editions of these operating systems running the default Windows Biometric Service are vulnerable.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity number for privilege elevation. EPSS information is not available, so the probability of exploitation in the wild is unknown, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a local authenticated user, as the service requires privileges that an authorized attacker can gain locally. The remediation is therefore urgent for any environment where local user credentials are not tightly controlled or where the Biometric Service is enabled.
OpenCVE Enrichment