Executive brief
Windows Biometric Service is a Microsoft system component that manages fingerprint and other biometric authentication on Windows devices. A use-after-free vulnerability allows an authenticated local user to execute code with elevated system privileges, potentially giving attackers full control over an affected machine.
Technical details
A use-after-free vulnerability exists in Microsoft Windows Biometric Service where freed memory is accessed after deallocation. An authorized local attacker can trigger this flaw to achieve privilege escalation from a user context to SYSTEM or higher. The vulnerability requires local code execution capabilities and authentication but does not require user interaction. A security patch is available from Microsoft through their standard update channels.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed