Executive brief
Windows Biometric Service is a Windows system component that processes fingerprint and other biometric authentication data. A heap buffer overflow vulnerability in this service allows an authorized local user to crash the system or execute arbitrary code with elevated privileges, potentially compromising system security and data integrity.
Technical details
A heap-based buffer overflow exists in the Windows Biometric Service that can be triggered by an authenticated local attacker. The vulnerability stems from insufficient bounds checking when processing biometric input data, allowing memory corruption. An attacker with local access and valid credentials can supply malformed biometric data to trigger the overflow, achieving privilege escalation or code execution with SYSTEM privileges. A security patch is available from Microsoft.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed
- 2026-09-08: advisory