Impact
A heap‑based buffer overflow in the Windows Biometric Service allows an attacker who is already authorized on the local system to raise their privileges to a higher level, potentially achieving system‑level access if the overflow is triggered successfully.
Affected Systems
Affected systems include Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2, Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1, as well as Microsoft Windows Server releases 2016, 2019, 2022 and 2025, including their server‑core installations.
Risk and Exploitability
With a CVSS score of 7.8, the vulnerability represents a moderate‑to‑high severity flaw; its exploitability relies on an adversary having local authorized access to trigger the heap overwrite in the biometric service, a scenario in which privilege escalation to SYSTEM or other elevated accounts can occur. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, indicating no known widespread exploitation currently but retaining significant risk for affected systems.
OpenCVE Enrichment