Executive brief
Windows Biometric Service is a Windows system component that handles fingerprint and other biometric authentication. A heap buffer overflow in this service allows an attacker with local system access to execute arbitrary code and escalate privileges, potentially gaining complete control of the affected computer.
Technical details
A heap-based buffer overflow vulnerability exists in the Windows Biometric Service, allowing an authorized local attacker to corrupt heap memory and achieve privilege escalation. The vulnerability requires local access and authentication to the system. An attacker can exploit this flaw to execute arbitrary code with elevated privileges, potentially achieving system-level compromise. A patch is available through Microsoft's security update process.
Affected products
- Microsoft Windows Biometric Service <UNKNOWN>
Timeline
- 2026-09-08: disclosed