CVE-2026-83968
massUse-After-Free Local Privilege Escalation in Windows Biometric Service
CVE-2026-83968 is a use-after-free memory-safety flaw in the Windows Biometric Service that Microsoft assigned and rated High (CVSS 3.1 7.8). An attacker who already has authorized low-privileged access on a local machine can trigger the flaw in the service, causing it to use freed memory and corrupt its execution. Successful exploitation allows the attacker to elevate privileges on the local system, gaining high confidentiality, integrity, and availability impact from that host. Affected systems are Windows installations running the Windows Biometric Service, though the data provided does not specify the affected Windows version ranges. As of this analysis there is no known in-the-wild exploitation, no public proof-of-concept, and a modest EPSS of 0.3% (25th percentile) for exploitation within 30 days.
What to do: Apply Microsoft's security update for CVE-2026-83968 as part of your regular patch cycle, prioritizing shared or multi-user Windows hosts where local privilege escalation has higher value. Because no public proof-of-concept or in-the-wild exploitation is known, this can be handled as standard-priority patching, but track Microsoft's advisory to confirm which Windows versions are affected and verify patch status on endpoints via your inventory/patch management tooling. Restricting local logon rights to untrusted users on sensitive systems reduces exposure while patching completes.
| Microsoft Windows Biometric Service (Windows operating system) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
- Weakness
- CWE-400, CWE-416
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.