Executive brief
Windows Biometric Service is a system component used for fingerprint and facial recognition authentication on Windows devices. A heap buffer overflow in this service allows an authorized user to execute arbitrary code with elevated privileges, potentially compromising the entire system including sensitive biometric data and corporate credentials.
Technical details
A heap-based buffer overflow vulnerability exists in the Windows Biometric Service that can be exploited by an authenticated local attacker to achieve privilege escalation. The vulnerability permits an authorized user to trigger a memory corruption condition through malformed biometric input or API calls to the service, enabling arbitrary code execution with SYSTEM privileges. The attack requires local access and prior authentication on the device. A fix is expected to be available through Windows Update.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed