Executive brief
Windows Biometric Service is a core operating system component that processes fingerprint and facial recognition data for user authentication. A heap-based buffer overflow vulnerability allows an authenticated local user to execute arbitrary code with elevated system privileges, potentially compromising the entire system.
Technical details
A heap-based buffer overflow exists in the Windows Biometric Service due to improper input validation in a buffer handling routine. The vulnerability requires an authenticated local attacker with user-level privileges to trigger via a specially crafted API call or malicious biometric input. Successful exploitation allows the attacker to overwrite heap memory structures and achieve privilege escalation to SYSTEM context, enabling complete system compromise. This is a local attack vector with no network component; patches are expected from Microsoft's security update process.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed