Impact
A heap-based buffer overflow in the Windows Biometric Service lets an attacker who already has local access elevate their privileges on the affected Windows system. The flaw is classified as CWE‑122 and could allow a malicious user or malware process to gain unauthorized higher privileges such as “User‑Account‑Control–enabled” rights or administrative access, potentially compromising system confidentiality, integrity, and availability.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; Windows Server 2016, Server 2019, Server 2022, Server 2025, including their Server Core editions.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity moderate‑high risk. EPSS is not available, so the exact exploitation probability is uncertain, but the flaw is not listed in the CISA KEV catalog. The likely attack vector is a local user situation; an adversary who can execute code on the machine or has an authorized user account can trigger the buffer overflow, which could be automated by malicious software. Given the lack of a publicly disclosed exploit, the risk is primarily contingent on the presence of the vulnerability in the system configuration and the attacker’s ability to run code locally.
OpenCVE Enrichment