Executive brief
Windows Biometric Service is a core Windows component that handles fingerprint and other biometric authentication on Windows systems. A heap-based buffer overflow vulnerability allows an authorized local user to write data beyond allocated memory boundaries, potentially enabling them to execute arbitrary code with system-level privileges and take complete control of the affected computer.
Technical details
A heap-based buffer overflow exists in the Windows Biometric Service due to insufficient input validation when processing biometric data. The vulnerability requires an authenticated local user with standard privileges to trigger the overflow condition. An attacker can craft malicious biometric input to corrupt heap memory and achieve arbitrary code execution in the context of the system service, leading to privilege escalation from standard user to SYSTEM level. Microsoft has issued a security patch to address this vulnerability.
Affected products
- Microsoft Windows Biometric Service
Timeline
- 2026-09-08: disclosed