Executive brief
Windows Biometric Service is a system component that manages fingerprint and other biometric authentication on Windows computers. A heap buffer overflow in this service allows an authorized user to execute code with elevated privileges, potentially taking complete control of the system. This could enable attackers to bypass security controls, steal sensitive data, or install persistent malware.
Technical details
A heap-based buffer overflow vulnerability exists in the Windows Biometric Service, a core Windows component handling biometric authentication. The vulnerability requires the attacker to already have local access and authorization to use the biometric service. By sending specially crafted input to the service, an attacker can overflow a heap buffer and overwrite memory, leading to privilege escalation from a standard user context to SYSTEM or another elevated privilege level. Exploitation requires local attack vector and prior authentication, but does not require user interaction. Microsoft has released patches to address this vulnerability.
Affected products
- Microsoft Windows Biometric Service
Timeline
- 2026-09-08: disclosed
- 2026-09-08: advisory