Impact
The flaw is a heap‑based buffer overflow in the Windows Biometric Service. When an attacker with local privileges manipulates the service’s memory handling, the overflow can overwrite adjacent memory, allowing the attacker to execute arbitrary code or change process privileges. The primary impact is elevated privilege on the local system, potentially granting the attacker administrative rights or the ability to run services with higher privileges. This weakness is classified as CWE‑122, a classic heap corruption issue.
Affected Systems
The issue affects all editions of Microsoft Windows 10 and Windows 11 from version 1607 through 26H1, as well as Windows Server 2016, 2019, 2022, and 2025, including Server Core installations. Every released build within the enumerated versions is vulnerable unless newer updates have been applied. Users of any of these operating systems should verify whether the relevant patch from Microsoft’s update guide has been installed.
Risk and Exploitability
With a CVSS score of 7.8, the vulnerability is considered high severity. No EPSS score is published, but the lack of a KEV listing does not diminish the potential risk, especially because the flaw only requires local access, which is commonly available on devices. The attack vector is likely a locally authenticated user executing a crafted request against the biometric service, making it a privilege escalation rather than a remote exploitation.
OpenCVE Enrichment