Impact
A heap‑based buffer overflow in the Windows Biometric Service can be triggered by a local user with authorized access, allowing that user to gain elevated privileges on the affected system.
Affected Systems
The flaw affects Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; Windows Server 2016, 2019, 2022, and 2025, including Server Core installations for all listed server editions.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity of the vulnerability. Because the exploit requires an authenticated local user, the attack vector is local.; the EPSS score is not available, and the vulnerability is not listed in CISA KEV, indicating no known widespread public exploitation. Nevertheless, an attacker with legitimate local credentials who can trigger the overflow can elevate privileges to system level, enabling full control over the compromised machine.
OpenCVE Enrichment