CVE-2026-83973
mass1Local privilege escalation via heap overflow in Microsoft Windows Biometric Service
CVE-2026-83973 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, the Windows component that processes fingerprint and facial-recognition authentication data (Windows Hello). An attacker who already holds a low-privileged account on a local machine can supply malformed data to the service, triggering a heap buffer overflow; the attack requires no user interaction. Successful exploitation allows the attacker to elevate privileges locally, with high impact on confidentiality, integrity, and availability on the compromised host (CVSS 3.1: 7.8, AV:L/PR:L/UI:N). Any Windows installation that ships the Biometric Service is potentially exposed, and the exact list of affected builds is defined by Microsoft's advisory rather than the summary data. Exploitation status: there is no public proof of concept, the flaw is not in CISA's KEV, and EPSS assigns only a 0.3% probability of exploitation in the next 30 days, indicating no known in-the-wild exploitation.
What to do: Apply Microsoft's security update for the affected Windows builds as specified in the vendor advisory; because no PoC or in-the-wild exploitation is known, this fits a high-priority regular patch cycle, prioritizing shared multi-user workstations, RDP-facing hosts, and machines with active biometric hardware. In the interim, restrict local logon to sensitive systems and monitor for Windows Biometric Service (WbioSrvc) crashes or unexpected child-process activity as an indicator of probing. Verify your deployed builds against Microsoft's advisory to confirm which machines require the update.
| Microsoft Windows (Windows Biometric Service) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.