Impact
A heap‑based buffer overflow in the Windows Biometric Service allows an authorized local attacker to gain elevated privileges. The vulnerability is a classic out‑of‑bounds write, identified as CWE‑122. The description explicitly states that exploitation requires an authorized local user, resulting in local privilege escalation.
Affected Systems
Microsoft Windows 10 versions 1607 through 22H2 and Microsoft Windows 11 versions 23H2 through 26H1 on all supported architectures, in addition to Microsoft Windows Server 2016, 2019, 2022, and 2025, including Server Core installations, are affected by this vulnerability.
Risk and Exploitability
The CVSS score of 7.8 classifies this vulnerability as high severity for local privilege escalation. The EPSS score is less than 1 %, indicating a low probability of exploitation, and it is not listed in the CISA KEV catalog. Exploitation is limited to a local attack context and requires an authorized user with device access; no remote attack vector or public exploit has been reported.
OpenCVE Enrichment