Impact
The flaw is a use‑after‑free in the Windows Biometric Service that permits an authorized local user to elevate privileges on the host. Exploitation could allow the attacker to execute arbitrary code with higher privileges, compromising confidentiality, integrity, and availability of the system.
Affected Systems
Microsoft Windows 10 version 1607, 1809, 21H2 (x86), Windows 10 22H2 (x64), Windows 11 23H2 (arm64 and x64), Windows 11 24H2 (arm64), Windows 11 25H2 (arm64), Windows 11 26H1 (x64), Windows Server 2016, Server 2016 (Server Core), Windows Server 2019, Server 2019 (Server Core), Windows Server 2022, Windows Server 2025, and Windows Server 2025 (Server Core).
Risk and Exploitability
The CVSS score is 7.8, indicating a high level of severity. EPSS is unavailable and the vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet been actively exploited in the wild. Attack requires local access and the victim must already be authenticated with an account that has permission to use biometric features. Given the lack of public exploits, the immediate risk to systems that have not applied the update is moderate, but the potential impact of a successful exploitation is significant.
OpenCVE Enrichment