CVE-2026-83955
massHeap Overflow in Windows Biometric Service Enables Local Privilege Escalation
CVE-2026-83955 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, which handles fingerprint, facial recognition, and other biometric authentication (Windows Hello) on Windows. A low-privileged but authorized local user can trigger the flaw by interacting with the Biometric Service, causing memory corruption without requiring user interaction. Successful exploitation allows the attacker to elevate privileges locally, gaining high confidentiality, integrity, and availability impact on the target system, effectively running at elevated/SYSTEM-level authority. Affected software includes Windows 10 (1607 through 22H2), Windows 11 (23H2 through 26H1), and Windows Server 2016 through 2025. As of this analysis there is no public proof-of-concept, no entry in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at only 0.2%, so no in-the-wild exploitation is known.
What to do: Apply Microsoft's security update for CVE-2026-83955 (monthly cumulative update) across all listed Windows 10, Windows 11, and Windows Server versions as soon as it is available, prioritizing end-user workstations and servers with Windows Hello or other biometric enrollment in use. In the interim, restrict local sign-in rights to trusted users, and inventory which endpoints have biometric devices/Windows Hello enabled to focus patching. Monitor Microsoft's advisory for updated patch details and for any changes in exploitation status.
| microsoft Windows 10 | 1607, 1809, 21H2, 22H2 |
| microsoft Windows 11 | 23H2, 24H2, 25H2, 26H1 |
| microsoft Windows Server 2016 | all supported releases per Microsoft's advisory |
| microsoft Windows Server 2019 | all supported releases per Microsoft's advisory |
| microsoft Windows Server 2022 | all supported releases per Microsoft's advisory |
| microsoft Windows Server 2025 | all supported releases per Microsoft's advisory |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.