Executive brief
Windows Biometric Service is a system component that processes biometric authentication data such as fingerprints and facial recognition. A heap-based buffer overflow vulnerability allows an authenticated local attacker to execute arbitrary code and gain system-level privileges, potentially compromising the entire system.
Technical details
A heap-based buffer overflow exists in Windows Biometric Service, allowing an authorized local attacker to trigger memory corruption through malformed input. The vulnerability requires local access and prior authentication to the system. Successful exploitation grants elevation of privileges from user mode to system/kernel mode, enabling full control over the affected machine. Microsoft has released security patches to remediate this issue.
Affected products
- Microsoft Windows Biometric Service
Timeline
- 2026-09-08: disclosed