Heap Buffer Overflow in Windows Biometric Service Enables Local Privilege Escalation
AI analysis
CVE-2026-83975 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, the Windows component that processes fingerprint and facial-recognition sign-in data. The CVSS vector (AV:L/AC:L/PR:L/UI:N) shows that an authorized local user can trigger the overflow with no user interaction and only standard user privileges required. Successful exploitation allows the attacker to elevate privileges locally, executing code in the service's high-privilege context (typically SYSTEM) with high impact on confidentiality, integrity and availability on the affected host. Every currently supported Windows release in the data is affected: Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2 through 26H1) and Windows Server 2016 through 2025, with local account access as the only prerequisite. As of the September 2026 Patch Tuesday release (973 vulnerabilities fixed), there is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, EPSS puts 30-day exploitation probability at only 0.3% (25th percentile), and it is not among the two zero-days Microsoft reported as actively exploited.
What to do: Apply Microsoft's September 2026 Patch Tuesday security updates for all affected Windows 10, Windows 11 and Windows Server versions (specific fixed build numbers were not provided in this data). Prioritize hosts with fingerprint or facial-recognition hardware and systems where untrusted local users can sign in, since the flaw requires only standard user privileges. As an interim measure where patching is delayed, restrict interactive sign-in rights on high-value machines to trusted accounts; no public exploit or workaround is known.
Affected
| microsoft Windows 10 | 1607 |
| microsoft Windows 10 | 1809 |
| microsoft Windows 10 | 21H2 |
| microsoft Windows 10 | 22H2 |
| microsoft Windows 11 | 23H2 |
| microsoft Windows 11 | 24H2 |
| microsoft Windows 11 | 25H2 |
| microsoft Windows 11 | 26H1 |
| microsoft Windows Server | 2016 |
| microsoft Windows Server | 2019 |
| microsoft Windows Server | 2022 |
| microsoft Windows Server | 2025 |
Estimated exposure
masswell over 1 billion devices (Windows 10/11 installed base plus tens of millions of Windows Server instances) — Microsoft has publicly stated the Windows 10/11 installed base exceeds 1.4 billion active devices and the Biometric Service ships with all affected client and server SKUs, so the potentially affected installed base is on the order of a…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.