Executive brief
Windows Biometric Service is a system component that handles fingerprint and other biometric authentication on Windows devices. An integer overflow vulnerability in this service allows an authenticated local attacker to escalate their privileges to system level, potentially gaining full control of the device.
Technical details
An integer overflow or wraparound vulnerability exists in the Windows Biometric Service that can be exploited by an authorized local attacker to achieve privilege escalation. The vulnerability is rooted in improper handling of numeric values in a critical code path within the biometric service. Exploitation requires local access and prior authentication to the system. A successful exploit allows an attacker to execute arbitrary code with elevated (SYSTEM) privileges, bypassing Windows security boundaries. Patches are available from Microsoft.
Affected products
- Microsoft Windows
Timeline
- 2026-09-08: disclosed