Executive brief
Windows Biometric Service is a system component that handles fingerprint and other biometric authentication on Windows devices. A heap buffer overflow vulnerability in this service allows a logged-in user to execute code with elevated system privileges, potentially compromising the entire device and its data.
Technical details
A heap-based buffer overflow exists in the Windows Biometric Service that can be triggered by an authenticated local attacker to achieve privilege escalation. The vulnerability requires an attacker to already have local access to the system. The buffer overflow condition allows an attacker to overwrite heap memory, enabling arbitrary code execution at a higher privilege level. No evidence of active exploitation in the wild has been reported. A patch is available from Microsoft via Windows security updates.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed