Executive brief
Windows Biometric Service is a core Windows component that manages fingerprint and other biometric authentication methods. A heap-based buffer overflow vulnerability allows an authenticated local user to execute arbitrary code with elevated system privileges, potentially leading to complete system compromise.
Technical details
A heap-based buffer overflow exists in the Windows Biometric Service, allowing an authorized local attacker to trigger a memory corruption condition. The vulnerability requires prior authentication and local network access to exploit. Successful exploitation grants the attacker SYSTEM-level privileges, enabling full system compromise including installing malware, modifying system files, and stealing sensitive data. Microsoft has released patches for this vulnerability.
Affected products
- Microsoft Windows Biometric Service <UNKNOWN>
Timeline
- 2026-09-08: disclosed