Impact
A heap-based buffer overflow exists within the Windows Biometric Service that permits an authorized local user to gain elevated privileges on the affected system. The flaw can be triggered by supplying crafted input to the service, causing it to write beyond a buffer boundary and potentially execute arbitrary code with higher privileges. This weakness is classified as CWE‑122 and allows attackers to compromise the integrity and confidentiality of the machine by acquiring administrative rights.
Affected Systems
The vulnerability impacts multiple Windows operating systems, including Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; and Windows Server releases from 2016 through 2025, both standard and Server Core installations. The specific hardware architectures affected are x86, x64, and arm64, depending on the OS version.
Risk and Exploitability
With a CVSS score of 7.8, the flaw represents a moderate to high risk. EPSS information is not available, and the vulnerability has not been listed in CISA's KEV catalog. The likely attack vector is local, requiring the attacker to have some level of authorized access to the target machine. Once exploited, the attacker can elevate privileges and potentially proceed to execute malicious payloads or compromise the entire system.
OpenCVE Enrichment