Executive brief
Windows Biometric Service is a core Windows component that manages fingerprint and biometric authentication for user login and application access. A heap buffer overflow vulnerability allows an attacker who already has local system access to escalate their privileges, potentially gaining administrative control over the affected computer and accessing all data and applications on it.
Technical details
A heap-based buffer overflow exists in Windows Biometric Service that can be triggered by an authorized local attacker. The vulnerability is rooted in improper buffer management within the biometric service code. Exploitation requires local system access (not remote) and results in privilege escalation from a lower privilege context to a higher one, likely enabling arbitrary code execution with elevated privileges. Microsoft has released patches to address this issue; affected systems should be updated immediately.
Affected products
- Microsoft Windows Biometric Service
Timeline
- 2026-09-08: disclosed