ZeroHour

CVE-2026-83954

mass

Heap Buffer Overflow in Windows Biometric Service Enables Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p24
Published
()
Modified
AI analysis

CVE-2026-83954 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, the Windows component that processes fingerprint, face, and other biometric authentication data (Windows Hello). A local, low-privileged user can trigger the flaw by getting the service to process crafted or malformed data, with no user interaction and no remote access required; because the service runs with high privileges, successful exploitation lets the attacker execute code at elevated privilege, gaining high-impact control over confidentiality, integrity, and availability on the local machine. All systems running the affected builds are in scope — Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2, 26H1), and Windows Server (2016, 2019, 2022, 2025) — since the Biometric Service ships as part of these operating systems. No exploitation has been reported: there is no public proof-of-concept, the CVE is not in CISA's KEV, and EPSS assigns roughly a 0.3% probability of exploitation within 30 days (25th percentile).

What to do: Install the Microsoft cumulative security update that addresses CVE-2026-83954 via Windows Update (or WSUS/Intune/SCCM) on all affected Windows 10, Windows 11, and Windows Server hosts, and verify the OS build is current afterward. Given no public PoC, no KEV listing, and ~0.3% EPSS, routine-cycle patching is defensible, but prioritize shared/RDS servers and workstations where untrusted users hold local logon rights. No workaround is documented; as a hedge, systems that never use biometric sign-in could have the Windows Biometric Service disabled until patched.

Affected
Microsoft Windows 101607, 1809, 21H2, 22H2
Microsoft Windows 1123H2, 24H2, 25H2, 26H1
Microsoft Windows Server2016, 2019, 2022, 2025
Estimated exposure
mass≈1 billion+ Windows devices and servers (the Biometric Service is present by default on every listed build) — The Windows 10/11 installed base is on the order of a billion devices (Microsoft and market-share reporting) and Windows Server adds millions of hosts, and since the vulnerable service ships by default in all listed builds, the affected…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.