Impact
A heap-based buffer overflow flaw exists in the authentication component of the Windows Biometric Service. When triggered, the overflow allows a local user with approved access to manipulate memory during biometric processing, resulting in elevated privileges on the affected machine. The primary impact is the gain of higher‑level rights, enabling the attacker to read or modify protected data, install software, or perform other unauthorized actions.
Affected Systems
Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; Windows Server 2016, 2019, 2022, and 2025, including core installations. All affected releases run the Windows Biometric Service by default.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity with local privilege escalation as the main vector. EPSS data is unavailable, but the lack of a KEV listing suggests limited current exploitation. An authorized attacker who can use the biometric service as a legitimate user can exploit the overflow, potentially escalating to administrator or SYSTEM level, and thereafter gain full control of the affected system.
OpenCVE Enrichment