Impact
A heap‐based buffer overflow in the Windows Biometric Service allows an authorized local user to gain elevated privileges. The flaw does not enable remote code execution; once triggered, the attacker can run arbitrary code with the service’s rights, effectively taking full control of the affected system.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2 and Windows 11 versions 23H2, 24H2, 25H2, and 26H1, including listed arm64 and x64 architectures, as well as Windows Server 2016, 2019, 2022, and 2025 in both standard and Server Core installations.
Risk and Exploitability
The CVSS score of 7.8 classifies the vulnerability as high severity. EPSS data is unavailable and it is not listed in the CISA KEV catalog, suggesting a low probability of widespread exploitation at present. However, the local privilege‑escalation capability means that any compromised system with the biometric service enabled is at serious risk, so rapid remediation is advised.
OpenCVE Enrichment