Executive brief
Windows Biometric Service is a system component that manages fingerprint and other biometric authentication on Windows devices. A heap-based buffer overflow in this service could allow an authorized user on a local machine to escalate their privileges to system level, gaining full control over the device and access to all stored data.
Technical details
A heap-based buffer overflow vulnerability exists in the Windows Biometric Service that can be triggered by an authenticated local attacker to achieve privilege escalation. The vulnerability requires local access and pre-existing authorization on the affected system. Successful exploitation allows an attacker to execute arbitrary code with SYSTEM privileges, bypassing normal access controls. A patch is expected to be available via Microsoft Security Updates.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed