Executive brief
Windows Biometric Service is a core operating system component that handles fingerprint, iris, and facial recognition authentication on Windows systems. A heap-based buffer overflow vulnerability allows an attacker with local access and existing system privileges to crash the service or execute arbitrary code with elevated permissions, potentially compromising system security and sensitive biometric data.
Technical details
A heap-based buffer overflow exists in Windows Biometric Service that can be triggered by an authenticated local attacker. The vulnerability occurs due to improper bounds checking when processing biometric data, allowing an attacker to write beyond allocated buffer boundaries. Exploitation requires local access and existing authentication credentials. Successful exploitation enables privilege escalation to SYSTEM level, granting full control over the affected machine. A patch is expected to be available through Microsoft's monthly security update cycle.
Affected products
- Microsoft Windows Biometric Service <UNKNOWN>
Timeline
- 2026-09-08: disclosed