Impact
A heap‑based buffer overflow occurs in the Windows Biometric Service, giving an authorized local user the ability to gain higher privileges on the affected system. This flaw is a Class 3 (CWE‑122) vulnerability that can be triggered when the service processes malformed data. The impact is that a user who can authenticate to the device may execute code with system or administrative rights, compromising the confidentiality, integrity, or availability of the machine. The flaw requires local access and does not enable remote exploitation.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Windows Server 2016, 2019, 2022, and 2025. These versions include the Windows Biometric Service component and are listed in the vendor product matrix for this vulnerability.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity, with a required local attacker having legitimate credentials to trigger the flaw. EPSS data is not available, so the probability of exploitation cannot be quantified at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, reducing the likelihood of widespread active exploitation but not eliminating the risk.
OpenCVE Enrichment