Executive brief
Windows Biometric Service is a core Windows component that handles fingerprint and biometric authentication. A heap buffer overflow in this service allows a locally authenticated attacker to execute arbitrary code with elevated privileges, potentially leading to full system compromise.
Technical details
A heap-based buffer overflow vulnerability exists in the Windows Biometric Service that can be exploited by an authenticated local attacker to achieve privilege escalation. The vulnerability does not require special privileges or user interaction beyond local system access. Successful exploitation allows an attacker to execute arbitrary code in the context of the Biometric Service process, potentially gaining SYSTEM-level privileges. Microsoft has released security patches to address this issue.
Affected products
- Microsoft Windows Biometric Service <UNKNOWN>
Timeline
- 2026-09-08: disclosed