Executive brief
Windows Biometric Service is a system component that manages fingerprint and iris scanning on Windows. A heap-based buffer overflow flaw allows an authenticated local user to crash the service or execute code with elevated privileges, potentially compromising the security of the entire system.
Technical details
A heap-based buffer overflow vulnerability exists in the Windows Biometric Service due to improper bounds checking when processing biometric input data. The flaw requires the attacker to have local authentication and user-level access to trigger the overflow condition. Successful exploitation allows an attacker to overwrite heap memory and achieve privilege escalation to SYSTEM level. A patch is available from Microsoft via the Security Update Guide.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed