CVE-2026-83970
massLocal Privilege Escalation via Heap Overflow in Windows Biometric Service
CVE-2026-83970 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, the built-in component that handles biometric sign-in (Windows Hello). An attacker who already has a limited local account on an affected machine can trigger the overflow and elevate privileges on that system; the CVSS vector confirms no user interaction is required. A successful exploit carries high impact for confidentiality, integrity, and availability, meaning the attacker gains near-complete control of the host at elevated privilege. The flaw affects Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2, 26H1), and Windows Server 2016 through 2025. No exploitation in the wild, public proof-of-concept, or CISA KEV listing is known, and EPSS estimates only a 0.3% probability of exploitation within 30 days.
What to do: Apply the Microsoft security update for CVE-2026-83970 to all affected Windows 10, Windows 11, and Windows Server systems, checking Microsoft's Security Update Guide or Windows Update for the patch applicable to each build (no KB number is provided in this data). Prioritize endpoints where untrusted or low-privileged users can log on, such as shared workstations, kiosks, and multi-user servers. If patching is delayed on systems where biometric sign-in is not required, evaluate whether the Biometric Service can be disabled as an interim risk reduction, and monitor Microsoft advisories for updates on exploitation status.
| microsoft Windows 10 | 1607, 1809, 21H2, 22H2 |
| microsoft Windows 11 | 23H2, 24H2, 25H2, 26H1 |
| microsoft Windows Server | 2016, 2019, 2022, 2025 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.