Executive brief
Windows Biometric Service is a core Windows component that manages fingerprint, facial, and iris recognition for user authentication. A heap buffer overflow vulnerability allows a logged-in user to execute arbitrary code and escalate their privileges to administrator level, potentially compromising system security and enabling unauthorized access to sensitive data.
Technical details
A heap-based buffer overflow exists in the Windows Biometric Service, a component responsible for processing biometric authentication data. The vulnerability can be exploited by an authenticated local attacker through a specially crafted request, allowing arbitrary code execution within the service's context and subsequent privilege escalation from user to system/SYSTEM level. The attack requires local access and prior authentication but no additional user interaction. Microsoft has issued a patch via its Security Update Guide; affected systems should apply available security updates immediately.
Affected products
- Microsoft Windows Biometric Service <UNKNOWN>
Timeline
- 2026-09-08: disclosed