ZeroHour

CVE-2026-83971

mass

Heap-Based Buffer Overflow in Windows Biometric Service (Local Privilege Escalation)

CVSS 3.1
7.8 high
EPSS
<1%p24
Published
()
Modified
AI analysis

CVE-2026-83971 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, the Windows component that manages fingerprint, facial-recognition, and other biometric authentication. An attacker who already holds a valid, low-privileged account on the machine can trigger the overflow through the service locally; no remote access or user interaction is required. Successful exploitation elevates the attacker's privileges on that local system, with high impact on confidentiality, integrity, and availability (CVSS 3.1 score 7.8). Any organization or user running the affected Windows releases - Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Windows Server 2016, 2019, 2022, and 2025 - is exposed, though exploitation requires local access to the device. There is currently no evidence of exploitation in the wild: the flaw is not in CISA's KEV catalog, no public proof-of-concept is known, and EPSS estimates only a 0.3% chance of exploitation within 30 days (25th percentile).

What to do: Install Microsoft's security update for CVE-2026-83971 via Windows Update, WSUS, or your patch-management tooling on all affected Windows 10, Windows 11, and Windows Server releases, and confirm the fix arrives in your next cumulative update cycle. Until patched, prioritize hosts that allow logon by untrusted or multiple users - shared workstations, kiosks, VDI and Remote Desktop Session hosts - and consider limiting biometric sign-in or the Windows Biometric Service where it is not required as an interim mitigation. Given no known exploitation, no public PoC, and low EPSS, standard patch cadence is defensible, but treat shared or multi-user systems as higher priority.

Affected
Microsoft Windows 101607, 1809, 21H2, 22H2
Microsoft Windows 1123H2, 24H2, 25H2, 26H1
Microsoft Windows Server2016, 2019, 2022, 2025
Estimated exposure
masshundreds of millions of Windows devices (affected releases span essentially the full supported Windows 10, Windows 11, and Windows Server installed base) — Microsoft has publicly reported roughly 1.4 billion monthly-active Windows 10/11 devices and the affected versions cover all currently serviced Windows releases, implying an affected install base in the hundreds of millions; this is an…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.