ZeroHour

CVE-2026-83972

mass

Heap buffer overflow in Windows Biometric Service allows local privilege escalation

CVSS 3.1
7.8 high
EPSS
<1%p24
Published
()
Modified
AI analysis

CVE-2026-83972 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, the Windows component that processes fingerprint and face-recognition sign-in data. An attacker who already holds valid credentials for a limited local account can trigger the overflow without user interaction by getting the service to process malformed data. Successful exploitation elevates the attacker's privileges on the local machine, with CVSS impact ratings indicating full compromise of confidentiality, integrity and availability on the host. All supported Windows client releases from Windows 10 1607 through Windows 11 26H1, plus Windows Server 2016 through 2025, are listed as affected, which in practice spans nearly the entire installed Windows base. There is currently no evidence of exploitation: the flaw is not in CISA KEV, has no known public proof-of-concept, and EPSS assigns only a 0.3% probability of exploitation within 30 days.

What to do: Apply Microsoft's security update for CVE-2026-83972, delivered through the regular monthly cumulative update channel, on all affected Windows 10/11 and Windows Server systems. Given the local, post-authentication attack vector and the absence of known exploitation, routine patch cycles are acceptable, but prioritize shared workstations, kiosks, and multi-user terminal/RDS servers where untrusted local accounts exist. On systems that do not use Windows Hello biometric sign-in, consider disabling the Windows Biometric Service (WbioSrvc) as an interim measure until patched.

Affected
Microsoft Windows 101607, 1809, 21H2, 22H2
Microsoft Windows 1123H2, 24H2, 25H2, 26H1
Microsoft Windows Server2016, 2019, 2022, 2025
Estimated exposure
mass≈1 billion+ Windows devices (the entire supported Windows 10/11/Server fleet; highest relevance on systems with fingerprint or IR cameras) — Windows 10/11 have an installed base on the order of a billion devices and the Biometric Service ships by default on every client and server release listed, so exposure is effectively the whole supported Windows estate even though the most…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.