Impact
An integer overflow or wraparound occurs in the Windows Biometric Service. When an authorized local attacker triggers this bug, the service processes a crafted value that exceeds the bounds of an integer variable, causing a misuse of the overflowed value to gain elevated privileges. The flaw is classed as a classic integer overflow problem (CWE‑190) and can lead to the attacker running code with system level permissions, modifying system configuration, installing malware, or exploiting further vulnerabilities. The impact is limited to the local machine but can compromise the entire system if the elevated account is used.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; Windows Server 2016, 2019, 2022, and 2025 (including Server Core installations).
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity for local privilege escalation. EPSS is not available, but the flaw requires the attacker to be an authorized local user, so the likelihood depends on user privileges and local environment. The vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation at this time. An attacker would need knowledge of the biometric service API and an ability to supply specific input that triggers the overflow, likely by interacting with the Windows Biometric Service APIs or drivers. Once exploited, the attacker gains full system control on the affected machine.
OpenCVE Enrichment