Impact
The problem is a heap-based buffer overflow in the Windows Biometric Service. An attacker who can run code in an authorized process can exploit the overflow to gain higher privileges on the local system. The flaw is identified as CWE‑122 and CWE‑20, permitting manipulation of privileged components and threatening confidentiality, integrity, and availability of the affected machine.
Affected Systems
Affected are Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2, Windows 11 versions 23H2, 24H2, 25H2, 26H1, and Windows Server families 2016, 2019, 2022, 2025 (including server core installations).
Risk and Exploitability
The CVSS score of 7.8 indicates high severity. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog, meaning known exploitation activity seems limited or undocumented. Attackers need local authorization, limiting the threat surface to systems where a user can run code. Because the flaw resides in a built‑in service, a successful exploit would elevate an attacker’s privileges to administrative level.
OpenCVE Enrichment