AI analysis
CVE-2026-83974 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, the Windows component that handles fingerprint, face, and other biometric authentication data. A local attacker who already holds valid low-privilege credentials can send crafted input to the service, overrunning a heap buffer and corrupting adjacent memory without any user interaction. Successful exploitation allows the attacker to elevate privileges, gaining high-level (typically SYSTEM) access with full confidentiality, integrity, and availability impact on the host. Any system running an affected Windows 10 or Windows 11 branch or an affected Windows Server release is in scope; the Biometric Service is present by default on these platforms, with exposure most relevant on systems where biometric logon (Windows Hello) is configured. As of the September 2026 Patch Tuesday release, there is no known public proof-of-concept, the flaw is not on the CISA KEV list, and EPSS puts 30-day exploitation probability at only 0.2% (16th percentile).
What to do: Apply Microsoft's September 2026 cumulative security updates (Patch Tuesday) to all affected Windows 10, Windows 11, and Windows Server systems; no KB-specific version numbers are provided in this data, so verify remediation against Microsoft's advisory for CVE-2026-83974. Prioritize hosts where local users hold low-privilege accounts and Windows Hello/biometric sign-in is enabled, and check the state of the Windows Biometric Service (WbioSrvc) on servers where it may be running. No public PoC or in-the-wild exploitation is known, so this can be handled in the regular patch cycle, but keep it on the list because local privilege escalations are commonly chained with other flaws.
Affected
| microsoft Windows 10 1607 (LTSC/Long-Term Servicing branch) | 1607 |
| microsoft Windows 10 1809 | 1809 |
| microsoft Windows 10 21H2 | 21H2 |
| microsoft Windows 10 22H2 | 22H2 |
| microsoft Windows 11 23H2 | 23H2 |
| microsoft Windows 11 24H2 | 24H2 |
| microsoft Windows 11 25H2 | 25H2 |
| microsoft Windows 11 26H1 | 26H1 |
| microsoft Windows Server 2016 | all supported builds |
| microsoft Windows Server 2019 | all supported builds |
| microsoft Windows Server 2022 | all supported builds |
| microsoft Windows Server 2025 | all supported builds |
Estimated exposure
masshundreds of millions of Windows 10/11 client devices plus millions of Windows Server instances across the eight client and four server branches listed — Windows 10 and Windows 11 together run on well over a billion active devices and the Biometric Service ships by default on every affected branch, so the broad CPE coverage across all supported Windows 10/11 and Server releases makes the…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.