Impact
A heap-based buffer overflow exists in the Windows Biometric Service, allowing an attacker who already has local access to the system to elevate privileges. The flaw applies when the service processes user data and can be triggered by crafting a malicious input that overflows an allocated buffer. Exploiting the overflow grants the attacker elevated rights, potentially enabling execution of arbitrary code or further attacks on the compromised machine.
Affected Systems
Affected are multiple Microsoft Windows operating systems: Windows 10 releases 1607, 1809, 21H2, and 22H2; Windows 11 releases 23H2, 24H2, 25H2, and 26H1; and Windows Server 2016, 2019, 2022, and 2025, including Server Core installations. All 32-bit and 64-bit variants of the mentioned editions are vulnerable as noted by the CPE entries.
Risk and Exploitability
The severity is reflected in a CVSS score of 7.8, indicating a high risk of local privilege escalation. EPSS data is unavailable, so the likelihood of exploitation cannot be quantified precisely. The vulnerability is not listed in the CISA KEV catalog, suggesting that it may not yet be widely exploited in the wild. Likely exploitation requires the attacker to be authenticated locally or to have the ability to craft a payload that the Biometric Service will process, meaning the attack vector is a local authorized attacker as inferred from the description.
OpenCVE Enrichment