CVE-2026-83954
massHeap Buffer Overflow in Windows Biometric Service Enables Local Privilege Escalation
CVE-2026-83954 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, the Windows component that processes fingerprint, face, and other biometric authentication data (Windows Hello). A local, low-privileged user can trigger the flaw by getting the service to process crafted or malformed data, with no user interaction and no remote access required; because the service runs with high privileges, successful exploitation lets the attacker execute code at elevated privilege, gaining high-impact control over confidentiality, integrity, and availability on the local machine. All systems running the affected builds are in scope — Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2, 26H1), and Windows Server (2016, 2019, 2022, 2025) — since the Biometric Service ships as part of these operating systems. No exploitation has been reported: there is no public proof-of-concept, the CVE is not in CISA's KEV, and EPSS assigns roughly a 0.3% probability of exploitation within 30 days (25th percentile).
What to do: Install the Microsoft cumulative security update that addresses CVE-2026-83954 via Windows Update (or WSUS/Intune/SCCM) on all affected Windows 10, Windows 11, and Windows Server hosts, and verify the OS build is current afterward. Given no public PoC, no KEV listing, and ~0.3% EPSS, routine-cycle patching is defensible, but prioritize shared/RDS servers and workstations where untrusted users hold local logon rights. No workaround is documented; as a hedge, systems that never use biometric sign-in could have the Windows Biometric Service disabled until patched.
| Microsoft Windows 10 | 1607, 1809, 21H2, 22H2 |
| Microsoft Windows 11 | 23H2, 24H2, 25H2, 26H1 |
| Microsoft Windows Server | 2016, 2019, 2022, 2025 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.