Executive brief
Windows Biometric Service is a system component used to manage fingerprint, iris, and other biometric authentication on Windows devices. A heap-based buffer overflow flaw allows an authorized local user to execute arbitrary code with elevated system privileges, potentially compromising device security and data integrity.
Technical details
A heap-based buffer overflow exists in the Windows Biometric Service due to improper bounds checking when processing biometric data. An authenticated local attacker can trigger the overflow by supplying malformed biometric input, allowing arbitrary code execution in the context of the service (typically SYSTEM). The vulnerability requires prior local system access and valid biometric authentication context; it is not remotely exploitable. Exploitation leads to privilege escalation from an authorized user to SYSTEM-level control. A patch has been made available through Microsoft's standard security update process.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed