ZeroHour

CVE-2026-83968

mass

Use-After-Free Local Privilege Escalation in Windows Biometric Service

CVSS 3.1
7.8 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-83968 is a use-after-free memory-safety flaw in the Windows Biometric Service that Microsoft assigned and rated High (CVSS 3.1 7.8). An attacker who already has authorized low-privileged access on a local machine can trigger the flaw in the service, causing it to use freed memory and corrupt its execution. Successful exploitation allows the attacker to elevate privileges on the local system, gaining high confidentiality, integrity, and availability impact from that host. Affected systems are Windows installations running the Windows Biometric Service, though the data provided does not specify the affected Windows version ranges. As of this analysis there is no known in-the-wild exploitation, no public proof-of-concept, and a modest EPSS of 0.3% (25th percentile) for exploitation within 30 days.

What to do: Apply Microsoft's security update for CVE-2026-83968 as part of your regular patch cycle, prioritizing shared or multi-user Windows hosts where local privilege escalation has higher value. Because no public proof-of-concept or in-the-wild exploitation is known, this can be handled as standard-priority patching, but track Microsoft's advisory to confirm which Windows versions are affected and verify patch status on endpoints via your inventory/patch management tooling. Restricting local logon rights to untrusted users on sensitive systems reduces exposure while patching completes.

Affected
Microsoft Windows Biometric Service (Windows operating system)
Estimated exposure
massplausibly hundreds of millions of Windows installations (Windows Biometric Service ships as a component of broadly deployed Windows releases) — The Windows installed base is on the order of a billion devices and the Biometric Service is present across modern Windows client editions, so the potentially affected population is an order of magnitude in the hundreds of millions, though…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-400, CWE-416
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.