Impact
The vulnerability is a heap-based buffer overflow in the Windows Biometric Service. An attacker who already has local access to a device can trigger the overflow, which can allow the attacker to execute code with higher privileges than their current session. This leads to a local elevation of privilege, potentially giving the attacker administrative rights. The weakness maps to CWE‑122, a classic heap buffer overflow.
Affected Systems
Microsoft Windows 10 releases from 1607 through 22H2, Microsoft Windows 11 releases from 23H2 through 26H1, and Microsoft Windows Server editions from 2016 to 2025 (including core installations) are affected. All these products are vulnerable when the Biometric Service is running. The vulnerability is present across different processor architectures, including x86, x64, and ARM64.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity. The EPSS score is not available, so the likelihood of exploitation cannot be quantified, but the vulnerability is not listed in CISA KEV, suggesting no widespread exploits are currently known. Because the attack requires an authorized local user, the risk is confined to environments where malicious insiders or compromised user accounts exist. Enterprises should treat this as a significant threat where privileged escalation could enable full system takeover.
OpenCVE Enrichment