Executive brief
Windows Biometric Service is a system component that processes fingerprint and facial recognition authentication on Windows. A heap buffer overflow in this service allows an authenticated local attacker to crash the service or execute arbitrary code with elevated system privileges, potentially compromising the entire computer.
Technical details
A heap-based buffer overflow vulnerability exists in the Windows Biometric Service due to improper input validation when processing biometric data. The vulnerability requires local authentication and interaction, but an attacker with valid credentials can trigger the overflow to achieve privilege escalation from a lower-privilege process to SYSTEM level. An attacker can craft malicious biometric input that overflows a heap buffer, enabling arbitrary code execution with elevated privileges. Patches are available from Microsoft Security Update Guide.
Affected products
- Microsoft Windows Biometric Service <UNKNOWN>
Timeline
- 2026-09-08: disclosed