Impact
A use‑after‑free flaw in Windows Biometric Service allows an attacker who already has local access to gain higher privileged rights. The vulnerability permits the execution of arbitrary code in a privileged context, potentially enabling the attacker to install malware, compromise data, or extend their foothold on the system. The weakness is characterized by CWE-400 (Uncontrolled Resource Consumption) and CWE-416 (Use After Free).
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; Windows Server 2016, 2019, 2022, and 2025, including Server Core installations. These contain the Windows Biometric Service component that is vulnerable.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity local privilege escalation risk. EPSS data is not available, so the probability of exploitation remains unknown, and the issue is not listed in the CISA KEV catalog. The flaw can be exploited by any authenticated user who can trigger the biometric service, making the attack vector local. No public exploit has been disclosed at the time of this analysis.
OpenCVE Enrichment