Executive brief
Windows Biometric Service, a system component used to authenticate users via fingerprint, face, or iris recognition, contains a heap memory corruption flaw. An attacker with local access can exploit this to gain elevated privileges and take full control of the system, bypassing normal security boundaries.
Technical details
A heap-based buffer overflow exists in the Windows Biometric Service (WBioSrvc), the operating system component that manages biometric authentication providers. The vulnerability requires the attacker to have local access and existing privileges (authorized user account) to exploit. By crafting malicious input or triggering specific conditions within the biometric service API, an attacker can corrupt heap memory and gain code execution in the context of the service, typically resulting in privilege escalation to SYSTEM level. The flaw is a memory safety issue in buffer handling within the biometric processing pipeline.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed