CVE-2026-83971
massHeap-Based Buffer Overflow in Windows Biometric Service (Local Privilege Escalation)
CVE-2026-83971 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, the Windows component that manages fingerprint, facial-recognition, and other biometric authentication. An attacker who already holds a valid, low-privileged account on the machine can trigger the overflow through the service locally; no remote access or user interaction is required. Successful exploitation elevates the attacker's privileges on that local system, with high impact on confidentiality, integrity, and availability (CVSS 3.1 score 7.8). Any organization or user running the affected Windows releases - Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Windows Server 2016, 2019, 2022, and 2025 - is exposed, though exploitation requires local access to the device. There is currently no evidence of exploitation in the wild: the flaw is not in CISA's KEV catalog, no public proof-of-concept is known, and EPSS estimates only a 0.3% chance of exploitation within 30 days (25th percentile).
What to do: Install Microsoft's security update for CVE-2026-83971 via Windows Update, WSUS, or your patch-management tooling on all affected Windows 10, Windows 11, and Windows Server releases, and confirm the fix arrives in your next cumulative update cycle. Until patched, prioritize hosts that allow logon by untrusted or multiple users - shared workstations, kiosks, VDI and Remote Desktop Session hosts - and consider limiting biometric sign-in or the Windows Biometric Service where it is not required as an interim mitigation. Given no known exploitation, no public PoC, and low EPSS, standard patch cadence is defensible, but treat shared or multi-user systems as higher priority.
| Microsoft Windows 10 | 1607, 1809, 21H2, 22H2 |
| Microsoft Windows 11 | 23H2, 24H2, 25H2, 26H1 |
| Microsoft Windows Server | 2016, 2019, 2022, 2025 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.