Impact
Windows Biometric Service contains a heap-based buffer overflow (CWE‑122) that allows an attacker who already has local authorization to gain elevated privileges on the affected Windows platform. The vulnerability arises when the service processes crafted biometric data that overflows a heap buffer, potentially allowing execution of arbitrary code with the service’s elevated rights. Successful exploitation would grant the user administrative authority, enabling them to modify system configurations, install malware, or compromise sensitive data, thereby affecting confidentiality, integrity, and availability at the system level.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, 26H1; Microsoft Windows Server 2016, 2019, 2022, and 2025 (including Server Core variants) are all affected. The vulnerability applies to both 32‑bit and 64‑bit builds as indicated by the known CPE set, and also affects ARM‑64 based Windows 11 releases.
Risk and Exploitability
The CVSS score of 7.8 denotes a high severity local privilege escalation; however, the EPSS score is not available, and the vulnerability is not currently listed in the CISA KEV catalog. The likely attack vector is local: an attacker needing legitimate access to run code (e.g., a compromised user or an application with user‑level privileges) can abuse the biometric service to inflate its rights. Because the flaw is a classic heap overflow, exploitation requires constructing a malicious input to the biometric service, which may be performed by a malware installer or a malicious application that is able to interact with the service.
OpenCVE Enrichment