Impact
The vulnerability is a heap-based buffer overflow in the Windows Biometric Service that allows an authorized user to run code with elevated privileges locally. Exploitation of this flaw would let a non‑privileged or moderately privileged user gain system‑wide rights on the affected machine, compromising confidentiality, integrity, and availability of the operating system.
Affected Systems
Affected vendors and products are Microsoft: Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Windows Server 2016, 2019, 2022, and 2025, including their Server Core installations. These include both 32‑bit and 64‑bit builds as noted in the CPE list.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity vulnerability. The EPSS score is not available, and the flaw is not listed in the CISA KEV catalog, suggesting no widespread public exploitation seen yet. The likely attack vector is local, requiring an authenticated user to interact with the Windows Biometric Service, after which the attacker can overflow a heap buffer and gain privileges. Without the patch, the attacker could execute arbitrary code with elevated rights, potentially compromising the entire system.
OpenCVE Enrichment