Executive brief
Windows Biometric Service is a system component that manages fingerprint and facial recognition authentication on Windows devices. An authorized attacker with local access can exploit an integer overflow vulnerability to gain elevated administrative privileges, potentially compromising the entire system and bypassing security controls.
Technical details
An integer overflow or wraparound vulnerability exists in the Windows Biometric Service that allows an authenticated local attacker to achieve privilege escalation. The vulnerability is reachable only by users with local access to the system. Exploitation enables an attacker with valid credentials to elevate privileges and gain system-level access. No patch availability information is provided in the advisory; consult Microsoft Security Response Center for remediation guidance.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed