ZeroHour

CVE-2026-83974

mass

Local Privilege Escalation via Heap Overflow in Windows Biometric Service

CVSS 3.1
7.8 high
EPSS
<1%p15
Published
()
Modified
AI analysis

CVE-2026-83974 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, the Windows component that handles fingerprint, face, and other biometric authentication data. A local attacker who already holds valid low-privilege credentials can send crafted input to the service, overrunning a heap buffer and corrupting adjacent memory without any user interaction. Successful exploitation allows the attacker to elevate privileges, gaining high-level (typically SYSTEM) access with full confidentiality, integrity, and availability impact on the host. Any system running an affected Windows 10 or Windows 11 branch or an affected Windows Server release is in scope; the Biometric Service is present by default on these platforms, with exposure most relevant on systems where biometric logon (Windows Hello) is configured. As of the September 2026 Patch Tuesday release, there is no known public proof-of-concept, the flaw is not on the CISA KEV list, and EPSS puts 30-day exploitation probability at only 0.2% (16th percentile).

What to do: Apply Microsoft's September 2026 cumulative security updates (Patch Tuesday) to all affected Windows 10, Windows 11, and Windows Server systems; no KB-specific version numbers are provided in this data, so verify remediation against Microsoft's advisory for CVE-2026-83974. Prioritize hosts where local users hold low-privilege accounts and Windows Hello/biometric sign-in is enabled, and check the state of the Windows Biometric Service (WbioSrvc) on servers where it may be running. No public PoC or in-the-wild exploitation is known, so this can be handled in the regular patch cycle, but keep it on the list because local privilege escalations are commonly chained with other flaws.

Affected
microsoft Windows 10 1607 (LTSC/Long-Term Servicing branch)1607
microsoft Windows 10 18091809
microsoft Windows 10 21H221H2
microsoft Windows 10 22H222H2
microsoft Windows 11 23H223H2
microsoft Windows 11 24H224H2
microsoft Windows 11 25H225H2
microsoft Windows 11 26H126H1
microsoft Windows Server 2016all supported builds
microsoft Windows Server 2019all supported builds
microsoft Windows Server 2022all supported builds
microsoft Windows Server 2025all supported builds
Estimated exposure
masshundreds of millions of Windows 10/11 client devices plus millions of Windows Server instances across the eight client and four server branches listed — Windows 10 and Windows 11 together run on well over a billion active devices and the Biometric Service ships by default on every affected branch, so the broad CPE coverage across all supported Windows 10/11 and Server releases makes the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

Microsoft September 2026 Patch Tuesday Fixes 973 Vulnerabilities and 2 Exploited Zero-Days

Microsoft's September 2026 Patch Tuesday fixes 973 vulnerabilities, including two zero-days already exploited in the wild.

Microsoft's September 2026 Patch Tuesday addresses 973 vulnerabilities across Windows, Office, and Azure components, including two zero-days already exploited in the wild. CVE-2026-81963, an elevation of privilege flaw in the Windows Update Stack, is flagged as an exploited zero-day. The release includes numerous remote code execution and information disclosure fixes for Microsoft Excel and Word, plus patches for the Windows kernel, ALPC, Print Spooler, ReFS, Entra ID, and Azure CLI.

GBHackers · 7d agoAdvisory in the wildCVE-2026-85880CVE-2026-85877CVE-2026-85875+27 CVEs