Executive brief
Windows Biometric Service is a system component that processes fingerprint and other biometric authentication data. A heap-based buffer overflow in this service could allow an authenticated user to crash the system or execute arbitrary code with elevated privileges, potentially compromising the entire system.
Technical details
A heap-based buffer overflow vulnerability exists in Windows Biometric Service that can be triggered by an authorized local attacker. The vulnerability allows an authenticated user to overflow a heap buffer, which can be leveraged to execute arbitrary code or corrupt memory structures. The attack requires local access and prior authentication to the system. Exploitation can result in privilege escalation from a standard user to a higher privilege level. A patch has been released by Microsoft.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed
- 2026-09-08: patched: Security update available from Microsoft