Executive brief
Windows Biometric Service, a Windows component that manages fingerprint and facial recognition data, contains a vulnerability allowing an authenticated local attacker to access sensitive personal information that should remain private. A successful exploit could expose user biometric data or related authentication credentials to an unauthorized party on the same system.
Technical details
The vulnerability is an information disclosure flaw in Windows Biometric Service that permits an authorized local attacker to access private personal information. The attack requires local access and authentication on the target system. An attacker with local access could exploit this to read sensitive biometric or credential data that should be protected. Patches are expected to be available from Microsoft through standard security updates.
Affected products
- Microsoft Windows Biometric Service
Timeline
- 2026-09-08: disclosed