Impact
A heap-based buffer overflow in the Windows Biometric Service allows an authorized user to gain elevated privileges locally. The overflow can be triggered by malicious input processed by the service, enabling the attacker to execute code with higher system privileges and potentially compromise the integrity and confidentiality of protected resources. This represents a medium‑to‑high risk vulnerability with the potential to allow a local user to bypass security controls.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, 26H1; and Microsoft Windows Server 2016 (including Server Core), 2019, 2022, and 2025 (including Server Core) are affected.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity for local privilege escalation. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no current public exploits are known. The attack requires an authenticated user with local access, making the exploitation scenario limited to systems where such an account exists. However, because the flaw is a buffer overflow, exploit development could be feasible, so the risk remains significant until a patch is applied.
OpenCVE Enrichment