CVE-2026-83969
massLocal Privilege Escalation via Heap Buffer Overflow in Windows Biometric Service
CVE-2026-83969 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, the component that handles Windows Hello fingerprint and facial-recognition authentication. An authorized, low-privileged local user can trigger the flaw by interacting with the service in a way that overflows a heap buffer; no user interaction or remote access is required. A successful exploit elevates the attacker's privileges from a standard local account to higher system privileges, with high impact on confidentiality, integrity, and availability of the machine. Affected systems span the listed Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2 through 26H1), and Windows Server (2016 through 2025) editions. There is no known public proof-of-concept, the flaw is not in the CISA KEV catalog, and its low EPSS (0.2%, 16th percentile) indicates no confirmed exploitation in the wild so far.
What to do: Deploy Microsoft's security update addressing CVE-2026-83969 across all listed Windows 10, Windows 11, and Windows Server systems in your next patch cycle, prioritizing machines where untrusted users have local sign-in rights (kiosks, shared workstations, terminal servers). Because the Windows Biometric Service is present on affected builds, treat all in-scope systems as potentially exposed even where Windows Hello is not actively used. No workaround is provided in the available data, so patching is the primary remediation.
| microsoft Windows 10 | 1607, 1809, 21H2, 22H2 |
| microsoft Windows 11 | 23H2, 24H2, 25H2, 26H1 |
| microsoft Windows Server | 2016, 2019, 2022, 2025 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.