Impact
A heap‑based buffer overflow in the Windows Biometric Service permits an attacker who is already authenticated on the host to overwrite memory and execute code with higher privileges. The vulnerability, classified as CWE-122, could allow the attacker to gain SYSTEM or other elevated rights, compromising confidentiality and integrity of the affected system.
Affected Systems
This flaw affects Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; and Windows Server 2016, 2019, 2022, 2025, including Server Core installations.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, while the EPSS score is not available and KEV does not list this issue. The flaw requires a local, authorized attacker, meaning it is most relevant in multi‑user environments where local accounts have elevated privileges. If exploited, the attacker can gain full control of the host.
OpenCVE Enrichment