Impact
A heap‑based buffer overflow occurs in the Windows Biometric Service, allowing an attacker with local, authorized access to gain elevated privileges. The flaw can overwrite critical memory structures during biometric authentication processing, potentially allowing the attacker to execute arbitrary code with higher rights. The vulnerability is classified as CWE‑122.
Affected Systems
The flaw affects a broad set of Microsoft Windows operating systems, including Windows 10 versions 1607, 1809, 21H2, 22H2, Windows 11 versions 23H2, 24H2, 25H2, 26H1, and corresponding Windows Server releases 2016, 2019, 2022, and 2025, both full and Core installations.
Risk and Exploitability
With a CVSS score of 7.8, the vulnerability poses a moderate to high risk. The EPSS score is not available, and the flaw is not listed in CISA's KEV catalog, indicating no publicly known exploits as of the latest data. The likely attack vector is local; an attacker must already have some level of access to the system to exploit the overflow, but can then raise their privileges within the local environment.
OpenCVE Enrichment