ZeroHour

CVE-2026-83970

mass

Local Privilege Escalation via Heap Overflow in Windows Biometric Service

CVSS 3.1
7.8 high
EPSS
<1%p24
Published
()
Modified
AI analysis

CVE-2026-83970 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, the built-in component that handles biometric sign-in (Windows Hello). An attacker who already has a limited local account on an affected machine can trigger the overflow and elevate privileges on that system; the CVSS vector confirms no user interaction is required. A successful exploit carries high impact for confidentiality, integrity, and availability, meaning the attacker gains near-complete control of the host at elevated privilege. The flaw affects Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2, 26H1), and Windows Server 2016 through 2025. No exploitation in the wild, public proof-of-concept, or CISA KEV listing is known, and EPSS estimates only a 0.3% probability of exploitation within 30 days.

What to do: Apply the Microsoft security update for CVE-2026-83970 to all affected Windows 10, Windows 11, and Windows Server systems, checking Microsoft's Security Update Guide or Windows Update for the patch applicable to each build (no KB number is provided in this data). Prioritize endpoints where untrusted or low-privileged users can log on, such as shared workstations, kiosks, and multi-user servers. If patching is delayed on systems where biometric sign-in is not required, evaluate whether the Biometric Service can be disabled as an interim risk reduction, and monitor Microsoft advisories for updates on exploitation status.

Affected
microsoft Windows 101607, 1809, 21H2, 22H2
microsoft Windows 1123H2, 24H2, 25H2, 26H1
microsoft Windows Server2016, 2019, 2022, 2025
Estimated exposure
massapproximately hundreds of millions of Windows installations (the vulnerable service ships as a default OS component in every affected Windows 10, Windows 11,… — The affected builds span essentially the entire supported Windows 10/11 desktop installed base plus Windows Server estates, and the Biometric Service is present by default on all of them; exploitation requires local access by a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.