ZeroHour

CVE-2026-83955

mass

Heap Overflow in Windows Biometric Service Enables Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p15
Published
()
Modified
AI analysis

CVE-2026-83955 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, which handles fingerprint, facial recognition, and other biometric authentication (Windows Hello) on Windows. A low-privileged but authorized local user can trigger the flaw by interacting with the Biometric Service, causing memory corruption without requiring user interaction. Successful exploitation allows the attacker to elevate privileges locally, gaining high confidentiality, integrity, and availability impact on the target system, effectively running at elevated/SYSTEM-level authority. Affected software includes Windows 10 (1607 through 22H2), Windows 11 (23H2 through 26H1), and Windows Server 2016 through 2025. As of this analysis there is no public proof-of-concept, no entry in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at only 0.2%, so no in-the-wild exploitation is known.

What to do: Apply Microsoft's security update for CVE-2026-83955 (monthly cumulative update) across all listed Windows 10, Windows 11, and Windows Server versions as soon as it is available, prioritizing end-user workstations and servers with Windows Hello or other biometric enrollment in use. In the interim, restrict local sign-in rights to trusted users, and inventory which endpoints have biometric devices/Windows Hello enabled to focus patching. Monitor Microsoft's advisory for updated patch details and for any changes in exploitation status.

Affected
microsoft Windows 101607, 1809, 21H2, 22H2
microsoft Windows 1123H2, 24H2, 25H2, 26H1
microsoft Windows Server 2016all supported releases per Microsoft's advisory
microsoft Windows Server 2019all supported releases per Microsoft's advisory
microsoft Windows Server 2022all supported releases per Microsoft's advisory
microsoft Windows Server 2025all supported releases per Microsoft's advisory
Estimated exposure
masshundreds of millions of Windows 10/11 and Server installations worldwide (a subset with biometric hardware/Windows Hello enrolled are the most directly… — The vulnerable Biometric Service ships by default in all listed Windows client and server versions, and the combined Windows 10/11 install base plus Windows Server enterprise deployments is on the order of a billion devices, though…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.