Executive brief
Windows Biometric Service is a system component that processes fingerprint and other biometric authentication data. A heap-based buffer overflow in this service allows an authorized user on the system to crash the service or execute code with elevated privileges, potentially compromising the security of the entire machine.
Technical details
A heap-based buffer overflow vulnerability exists in Windows Biometric Service, triggered when processing specially crafted input. The vulnerability requires prior authorization and local access to the system. An attacker with an existing user account can exploit this to corrupt heap memory and achieve privilege escalation, gaining access to system-level capabilities. The attack vector is local; no network access is required.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed