Impact
A heap-based buffer overflow in the Windows Biometric Service allows an authorized attacker to gain elevated local privileges. The flaw resides in the way the service processes biometric data and can be triggered by a crafted input that overflows an internal buffer, resulting in arbitrary code execution with the service’s privileges.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Windows Server 2016, 2019, 2022, and 2025, including Server Core installations, are affected.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity local vulnerability, and the EPSS score is currently unavailable, making the exploitation probability unclear. The vulnerability is not listed in the CISA KEV catalog, and no publicly reported exploits are documented at this time. Nonetheless, an attacker with local access can exploit the service by providing malicious biometric input to trigger the buffer overflow, thereby elevating their privileges on the affected system.
OpenCVE Enrichment