Executive brief
Windows Biometric Service is a system component that manages fingerprint and iris scanning on Windows devices. A heap buffer overflow in this service allows an authorized local user to execute arbitrary code with elevated privileges, potentially enabling takeover of the affected system.
Technical details
A heap-based buffer overflow exists in the Windows Biometric Service, a privileged system component responsible for biometric authentication. The vulnerability is triggered when processing malformed input during local operations. An attacker with local access and authorization to interact with the biometric service can overflow a heap buffer to corrupt memory and escalate privileges to SYSTEM level. The attack requires local access and prior authorization but does not require user interaction or network connectivity. A patch is available from Microsoft.
Affected products
- Microsoft Windows Biometric Service
Timeline
- 2026-09-08: disclosed