Impact
The vulnerability is a heap‑based buffer overflow in the Windows Biometric Service that can be triggered by a user with local privileges. Successful exploitation lets an attacker overwrite memory in the service, elevating their privileges to the SYSTEM level and potentially allowing arbitrary code execution. This weakness maps to CWE‑122, indicating unsafe buffer handling.
Affected Systems
Affected Microsoft Windows releases include Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Windows Server editions 2016, 2019, 2022, and 2025, both in full installation and Server Core forms. The flaw resides in the default Windows Biometric Service component across all these platforms.
Risk and Exploitability
The CVSS score of 7.8 marks the flaw as high severity, yet EPSS data is not available and the vulnerability is not listed in CISA KEV, implying limited public exploitation evidence. The attack vector is local, requiring the attacker to be authenticated to the machine, but the service runs as SYSTEM, so the impact of a successful overflow is the ability to execute code with full system privileges. Until the vendor patch is applied, systems with the biometric service enabled remain at a substantial risk.
OpenCVE Enrichment