Impact
The vulnerability is a heap‑based buffer overflow in the Windows Biometric Service that permits an attacker who already has local access to the system to elevate their privileges. This flaw satisfies CWE‑122, a classic overflow that can overwrite critical memory structures, enabling the attacker to gain higher access rights. No remote component is required; the exploitation is confined to a locally authorized user.
Affected Systems
The flaw affects Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2, Windows 11 versions 23H2, 24H2, 25H2, 26H1, as well as Windows Server 2016, 2019, 2022, and 2025, including their Server Core installations.
Risk and Exploitability
The CVSS score of 7.8 marks it as high severity, though the EPSS score is unknown. It is not listed in CISA’s KEV catalog, suggesting no publicly known exploits yet. The likely attack vector is local privilege escalation from an authorized user, with no requirement for network or remote code execution. Given the high severity and the local nature, systems with standard user accounts should prioritize patching.
OpenCVE Enrichment