Impact
A heap‑based buffer overflow in the Windows Biometric Service allows an attacker who already has local user access to elevate their privileges. The flaw arises when the service fails to check the bounds of a heap allocation during processing of biometric credentials, as identified by CWE‑122. If successfully exploited, the attacker can gain higher privileges, enabling them to modify protected system settings, install malware, or bypass security controls within the affected Windows environments.
Affected Systems
The vulnerability impacts Microsoft Windows 10 releases from version 1607 through 22H2, Windows 11 versions up to 26H1, and a range of Windows Server editions including 2016, 2019, 2022, and 2025. All cited builds, including standard and server core installations, are affected by the flaw.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity local privilege escalation risk, but no EPSS score is currently available to quantify exploit probability. The vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation has been documented. The likely attack vector requires the attacker to be authenticated on the target machine and rely on the local user context to trigger the context switch triggered by the overflow.
OpenCVE Enrichment