CVE-2026-83972
massHeap buffer overflow in Windows Biometric Service allows local privilege escalation
CVE-2026-83972 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, the Windows component that processes fingerprint and face-recognition sign-in data. An attacker who already holds valid credentials for a limited local account can trigger the overflow without user interaction by getting the service to process malformed data. Successful exploitation elevates the attacker's privileges on the local machine, with CVSS impact ratings indicating full compromise of confidentiality, integrity and availability on the host. All supported Windows client releases from Windows 10 1607 through Windows 11 26H1, plus Windows Server 2016 through 2025, are listed as affected, which in practice spans nearly the entire installed Windows base. There is currently no evidence of exploitation: the flaw is not in CISA KEV, has no known public proof-of-concept, and EPSS assigns only a 0.3% probability of exploitation within 30 days.
What to do: Apply Microsoft's security update for CVE-2026-83972, delivered through the regular monthly cumulative update channel, on all affected Windows 10/11 and Windows Server systems. Given the local, post-authentication attack vector and the absence of known exploitation, routine patch cycles are acceptable, but prioritize shared workstations, kiosks, and multi-user terminal/RDS servers where untrusted local accounts exist. On systems that do not use Windows Hello biometric sign-in, consider disabling the Windows Biometric Service (WbioSrvc) as an interim measure until patched.
| Microsoft Windows 10 | 1607, 1809, 21H2, 22H2 |
| Microsoft Windows 11 | 23H2, 24H2, 25H2, 26H1 |
| Microsoft Windows Server | 2016, 2019, 2022, 2025 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.