ZeroHour

CVE-2026-83969

mass

Local Privilege Escalation via Heap Buffer Overflow in Windows Biometric Service

CVSS 3.1
7.8 high
EPSS
<1%p15
Published
()
Modified
AI analysis

CVE-2026-83969 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, the component that handles Windows Hello fingerprint and facial-recognition authentication. An authorized, low-privileged local user can trigger the flaw by interacting with the service in a way that overflows a heap buffer; no user interaction or remote access is required. A successful exploit elevates the attacker's privileges from a standard local account to higher system privileges, with high impact on confidentiality, integrity, and availability of the machine. Affected systems span the listed Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2 through 26H1), and Windows Server (2016 through 2025) editions. There is no known public proof-of-concept, the flaw is not in the CISA KEV catalog, and its low EPSS (0.2%, 16th percentile) indicates no confirmed exploitation in the wild so far.

What to do: Deploy Microsoft's security update addressing CVE-2026-83969 across all listed Windows 10, Windows 11, and Windows Server systems in your next patch cycle, prioritizing machines where untrusted users have local sign-in rights (kiosks, shared workstations, terminal servers). Because the Windows Biometric Service is present on affected builds, treat all in-scope systems as potentially exposed even where Windows Hello is not actively used. No workaround is provided in the available data, so patching is the primary remediation.

Affected
microsoft Windows 101607, 1809, 21H2, 22H2
microsoft Windows 1123H2, 24H2, 25H2, 26H1
microsoft Windows Server2016, 2019, 2022, 2025
Estimated exposure
masshundreds of millions of Windows devices (listed versions cover the mainstream Windows 10/11 desktop and Windows Server install base) — The affected version list spans essentially the entire mainstream Windows 10/11 client and Windows Server population, whose combined installed base is publicly estimated in the hundreds of millions of devices.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.