Executive brief
Windows Biometric Service is a core Windows component that processes biometric authentication data such as fingerprints. A heap buffer overflow vulnerability allows an attacker with local system access to escalate privileges, potentially gaining complete control of the system.
Technical details
A heap-based buffer overflow exists in Windows Biometric Service, triggered when processing specially crafted biometric input data. The vulnerability requires the attacker to already have local access to the system but does not require elevated privileges initially. Successful exploitation allows arbitrary code execution in the security context of the Biometric Service, enabling privilege escalation to SYSTEM level. The vulnerability is classified as high severity with a CVSS score of 7.8 and has not been observed exploited in the wild as of the advisory date. A security patch is expected from Microsoft.
Affected products
- Microsoft Windows Biometric Service
Timeline
- 2026-09-08: disclosed