Impact
The flaw is a local information disclosure in the Windows Biometric Service that can allow an actor with legitimate user access to view private personal information. It represents a confidentiality breach as the attacker can read data not intended for them. The weakness is identified as CWE-359, "Information Exposure through an Accessible Mechanism."
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2 and Windows 11 versions 23H2, 24H2, 25H2, 26H1 as well as Windows Server 2016, 2019, 2022, 2025 (including Core installations).
Risk and Exploitability
The vulnerability carries a CVSS score of 5.5, indicating moderate risk. Exploitation requires local, authorized access and no remote entry point is reported. The EPSS score is not available, so the likelihood of exploitation at this time is unknown. The vulnerability is not listed in CISA’s KEV catalog, suggesting no confirmed large‑scale exploitation currently. The likely attack vector is an attacker with legitimate user privileges using the Biometric Service to retrieve personal data.
OpenCVE Enrichment