Impact
The Windows Biometric Service contains a heap-based buffer overflow vulnerability (CWE‑122) that allows an attacker with local access to the system to execute crafted code with elevated privileges. When the overflow is triggered, the attacker can gain administrative rights and fully control the affected machine. The flaw arises from improper handling of biometric data buffers, which can be corrupted by malicious input.
Affected Systems
Affected Microsoft products include Windows 10 releases 1607, 1809, 21H2 and 22H2; Windows 11 releases 23H2, 24H2, 25H2 and 26H1; and Windows Server 2016, 2019, 2022 and 2025, including all Server Core installations. All listed operating system releases are susceptible to the elevation of privilege flaw.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.8, indicating high severity, but the EPSS score is not available and the flaw is not listed in the CISA KEV catalog, suggesting limited publicly known exploitation. The attack vector is local, requiring the attacker to have authorized access to the system to trigger the heap overflow. Because the flaw is local, its impact is confined to the affected machine rather than a network-wide compromise.
OpenCVE Enrichment