Executive brief
Windows Biometric Service is a system component that manages fingerprint and other biometric authentication on Windows devices. A use-after-free memory flaw allows an authorized local user to execute arbitrary code with elevated privileges, potentially gaining administrative access to the system and compromising sensitive company data or systems connected to it.
Technical details
A use-after-free vulnerability exists in the Windows Biometric Service, where freed memory is subsequently accessed under attacker-controlled conditions. The flaw requires the attacker to be an authenticated local user with the ability to interact with the affected service. Exploitation permits local privilege escalation, enabling an attacker to run code with SYSTEM or higher privileges. The vulnerability is memory corruption in nature and affects the service's handling of internal data structures. A patch is available from Microsoft Security Response Center.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed