Executive brief
Windows Biometric Service is a core Windows component responsible for managing fingerprint and biometric authentication on computers. A heap-based buffer overflow in this service allows an authorized local attacker to crash the system or execute arbitrary code with elevated privileges, potentially gaining full administrative control of the affected computer.
Technical details
This vulnerability is a heap-based buffer overflow in Microsoft Windows Biometric Service that can be triggered by an authenticated local attacker. The flaw allows an attacker with valid user credentials to overflow a heap buffer, leading to memory corruption. Successful exploitation results in privilege escalation, enabling the attacker to execute code with SYSTEM-level privileges. The attack requires local access and prior authentication; it is not remotely exploitable over the network. A patch has been released by Microsoft and should be applied immediately to affected systems.
Affected products
- Microsoft Windows Biometric Service <UNKNOWN>
Timeline
- 2026-09-08: disclosed