Impact
A heap‑based buffer overflow in Windows Biometric Service, identified as CWE‑122, allows an attacker who can already execute code on the system to obtain elevated privileges. The flaw occurs when the service processes biometric input, leading to memory corruption that can be exploited to run arbitrary code with system privileges. The impact is direct: the compromised user gains the ability to modify system configuration, install software, or access protected data, effectively turning a local user into a root‑level actor.
Affected Systems
The vulnerability affects Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; and Windows Server 2016, 2019 (both full and Server Core), 2022, and 2025 (including Server Core). All listed builds, regardless of architecture, are susceptible to the flaw.
Risk and Exploitability
The CVSS score of 7.8 places this bug in the high‑severity class, indicating significant risk if exploited. The EPSS score is not available, so there is currently no evidence of widespread exploitation, and the vulnerability is not listed in the CISA KEV catalog. The primary attack vector is local: an attacker must already have authorization to execute code on the target machine. Once the buffer overflow is triggered, the attacker can elevate privileges to system level. Because the flaw requires local access, exploitation is limited to environments where an attacker can run code with user credentials on the machine.
OpenCVE Enrichment