Impact
The Windows Biometric Service contains a heap‑based buffer overflow that allows an attacker with local user privileges to trigger an overflow and elevate privileges. By overflowing the heap, the attacker can execute arbitrary code with higher privileges, enabling full control over the system.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1; Microsoft Windows Server versions 2016, 2019, 2022, and 2025, including Server Core installations.
Risk and Exploitability
The CVSS score of 7.8 indicates a moderate severity risk, and no EPSS data is available. The flaw is not listed in the CISA KEV catalog, suggesting that exploitation activity is currently unknown. The likely attack vector is local; an attacker who already has user-level access can trigger the overflow by interacting with the Biometric Service, potentially while authenticating or using a biometric device, and then gain elevated privileges, compromising confidentiality, integrity, and availability of the affected system.
OpenCVE Enrichment