Impact
A heap‑based buffer overflow exists in the Windows Biometric Service. The flaw can be triggered by an attacker who already has local access to the system, allowing them to gain elevated privileges on that machine. The vulnerability is classified as CWE-122 and can compromise the confidentiality, integrity, and availability of the affected system by enabling an attacker to execute arbitrary code or inject malicious operations with higher privileges.
Affected Systems
Microsoft Windows 10 version 1607, 1809, 21H2, 22H2; Windows 11 version 23H2, 24H2, 25H2, 26H1; Windows Server 2016 (including Server Core), 2019, 2022, 2025 (including Server Core). The affected builds were identified via Microsoft public advisories and the common platform enumeration list provided.
Risk and Exploitability
The CVSS score of 7.8 indicates a high overall risk. Because the attack requires local access, an authorized or locally compromised user may exploit the overflow without needing network connectivity. EPSS data is currently unavailable, so the real‑time probability of exploitation cannot be quantified, but the flaw is known and has not been listed in the CISA KEV catalog yet. An attacker who can trick the biometric service into processing crafted input could elevate privileges, potentially compromising the entire operating environment. The lack of a public patch as of the data time emphasizes the importance of early mitigation.
OpenCVE Enrichment