CVE-2026-83967
massHeap overflow in Windows Biometric Service enables local privilege escalation
CVE-2026-83967 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, which ships with Windows 10, Windows 11, and supported Windows Server releases. A local, low-privileged authorized attacker can send crafted input to the service to trigger the heap overflow, with no user interaction required. Successful exploitation yields an elevation-of-privilege condition with high impact on confidentiality, integrity, and availability, giving the attacker greater control over the local host. Any installation of Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2, 26H1), or Windows Server 2016/2019/2022/2025 is affected. No exploitation is known: there is no public proof-of-concept, the CVE is not in CISA's KEV catalog, and EPSS assigns a low 0.3% probability of exploitation within 30 days (25th percentile).
What to do: Apply Microsoft's latest cumulative security update for all listed Windows 10, Windows 11, and Windows Server versions as soon as it is released through Windows Update/WSUS, and confirm remediation by checking the updated OS build. Until patched, prioritize shared, multi-user, and remotely accessed hosts where low-privileged users can log on; on machines that do not use Windows Hello biometric sign-in, the Windows Biometric Service (WbioSrvc) can be stopped or disabled as an interim mitigation. With no public PoC and no observed in-the-wild exploitation, standard patch cadence is acceptable, but this flaw should be tracked until the update is deployed.
| microsoft Windows 10 | 1607, 1809, 21H2, 22H2 |
| microsoft Windows 11 | 23H2, 24H2, 25H2, 26H1 |
| microsoft Windows Server | 2016, 2019, 2022, 2025 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.