Impact
Heap-based buffer overflow in the Windows Biometric Service provides a local privilege escalation path. An attacker who can successfully trigger the vulnerability can gain higher privileges, potentially executing code with elevated rights. The weakness is a classic heap overflow (CWE-122).
Affected Systems
Microsoft Windows 10 (versions 1607, 1809, 21H2, 22H2), Microsoft Windows 11 (versions 23H2, 24H2, 25H2, 26H1), Microsoft Windows Server 2016 (including Server Core), Windows Server 2019 (including Server Core), Windows Server 2022, and Windows Server 2025 (including Server Core).
Risk and Exploitability
The CVSS score of 7.8 classifies this vulnerability as high severity, indicating a significant risk if exploited. EPSS data is unavailable, and the vulnerability is not listed in CISA's KEV catalog, so current public exploitation data is limited. The attack vector is local, relying on an authorized user to trigger the heap overflow, which suggests that privileged or relatively trusted accounts could be used to achieve escalation. Though there are no publicly available exploits at the time of this analysis, the high severity and local privilege escalation nature warrant prompt remediation.
OpenCVE Enrichment