Impact
A heap-based buffer overflow occurs in the Windows Biometric Service. The flaw allows a local user who can access the biometric interface to write beyond a buffer and gain elevated privileges on the system, potentially enabling the execution of arbitrary code with higher privileges.
Affected Systems
The vulnerability affects Microsoft Windows 10, 1607 through 22H2, Windows 11, 23H2 through 26H1, and the corresponding Windows Server releases (2016, 2019, 2022, 2025), including both server core and full installations. The affected builds are specified by the list of Windows versions provided and include various processor architectures such as x86, x64, and ARM64.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity local privilege elevation. While the EPSS score is not available and the vulnerability is not listed in the KEV catalog, the required attacker is a local, authorized user. This limits the reach of the exploit but still poses a serious risk if an attacker gains user access. No public exploit is documented in the supplied data, and the attack vector is inferred to be through local biometric operations.
OpenCVE Enrichment