Impact
A heap-based buffer overflow exists in Windows Biometric Service that lets an attacker with local authorization elevate privileges within the affected operating system. The flaw arises when the service processes biometric data and fails to bound check heap allocations, enabling memory corruption and control‑flow hijack. The result is that the attacker can start processes or services with higher privileges than intended, potentially accessing protected resources, installing software, or modifying system settings.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, 26H1; Microsoft Windows Server editions 2016, 2019, 2022, and 2025 (including Server Core installations).
Risk and Exploitability
The vulnerability carries a CVSS score of 7.8, categorizing it as high severity. No EPSS score is currently available, and the issue is not listed in the CISA KEV catalog, meaning no confirmed exploitation reports. The attack vector is inferred to be local; an authorized user would need to trigger the overflow by interacting with the biometric service. The impact is limited to the machine where the exploit is executed, but privilege escalation can enable broader system compromise if the attacker obtains administrative rights.
OpenCVE Enrichment