Executive brief
Windows Biometric Service is a core Windows component that manages biometric authentication data. A heap-based buffer overflow in this service allows an attacker with network access and valid credentials to crash the service or execute arbitrary code, potentially gaining elevated privileges on the system.
Technical details
A heap-based buffer overflow vulnerability exists in the Windows Biometric Service due to insufficient bounds checking when processing biometric data. An authenticated attacker with network access can send a specially crafted request to trigger the overflow, corrupting heap memory and potentially achieving remote code execution with elevated privileges. The vulnerability requires the attacker to be authenticated and have network connectivity to the target system.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed