Impact
The vulnerability is a null pointer dereference in the Windows Biometric Service. An attacker who is authorized to use the biometric functionality can trigger the crash and receive elevated privileges within the local system context. This flaw stems from improper validation of pointer values and is classified under CWE-476. The resulting privilege escalation lets the attacker execute arbitrary code, install malware, or modify system configuration, thereby compromising the confidentiality, integrity, and availability of the affected machine.
Affected Systems
Affected systems include Microsoft Windows 10 build 1607, 1809, 21H2, and 22H2, as well as Windows 11 builds 23H2, 24H2, 25H2, and 26H1. All corresponding Server Core installations of Windows Server 2016, 2019, 2022, and 2025 are also impacted. The flaw exists in the service’s core code and therefore applies to all user accounts that have permissions to access biometric authentication facilities.
Risk and Exploitability
The CVSS base score is 7.8, denoting moderate to high severity, but the EPSS score is less than 1%, indicating a low exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Because it requires the attacker to already have local authorization—i.e., the ability to use biometric authentication—the attack vector is likely local and privileged. Once triggered, the null pointer dereference grants the attacker system‑level privileges on the machine, allowing full control over the compromised system.
OpenCVE Enrichment