Impact
Heap-based buffer overflow in the Windows Biometric Service allows an authorized attacker to elevate privileges locally. The flaw, identified as CWE-122, enables the attacker to execute code with higher privileges, potentially taking full control over the affected machine. This local privilege escalation could be used to compromise sensitive data or further exploit the system during the attack.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, 26H1; Microsoft Windows Server 2016, 2019, 2022, 2025 (including Server Core installations).
Risk and Exploitability
The CVSS score is 7.8, indicating a high‑severity local privilege escalation. The EPSS score is not available, so the exploitation probability cannot be assessed. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a local authorized user or misused application; an attacker would need access to the machine to trigger the heap overflow and elevate privileges. No remote exploitation vector is described.
OpenCVE Enrichment