ZeroHour

CVE-2026-83975

mass

Heap Buffer Overflow in Windows Biometric Service Enables Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p24
Published
()
Modified
AI analysis

CVE-2026-83975 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, the Windows component that processes fingerprint and facial-recognition sign-in data. The CVSS vector (AV:L/AC:L/PR:L/UI:N) shows that an authorized local user can trigger the overflow with no user interaction and only standard user privileges required. Successful exploitation allows the attacker to elevate privileges locally, executing code in the service's high-privilege context (typically SYSTEM) with high impact on confidentiality, integrity and availability on the affected host. Every currently supported Windows release in the data is affected: Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2 through 26H1) and Windows Server 2016 through 2025, with local account access as the only prerequisite. As of the September 2026 Patch Tuesday release (973 vulnerabilities fixed), there is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, EPSS puts 30-day exploitation probability at only 0.3% (25th percentile), and it is not among the two zero-days Microsoft reported as actively exploited.

What to do: Apply Microsoft's September 2026 Patch Tuesday security updates for all affected Windows 10, Windows 11 and Windows Server versions (specific fixed build numbers were not provided in this data). Prioritize hosts with fingerprint or facial-recognition hardware and systems where untrusted local users can sign in, since the flaw requires only standard user privileges. As an interim measure where patching is delayed, restrict interactive sign-in rights on high-value machines to trusted accounts; no public exploit or workaround is known.

Affected
microsoft Windows 101607
microsoft Windows 101809
microsoft Windows 1021H2
microsoft Windows 1022H2
microsoft Windows 1123H2
microsoft Windows 1124H2
microsoft Windows 1125H2
microsoft Windows 1126H1
microsoft Windows Server2016
microsoft Windows Server2019
microsoft Windows Server2022
microsoft Windows Server2025
Estimated exposure
masswell over 1 billion devices (Windows 10/11 installed base plus tens of millions of Windows Server instances) — Microsoft has publicly stated the Windows 10/11 installed base exceeds 1.4 billion active devices and the Biometric Service ships with all affected client and server SKUs, so the potentially affected installed base is on the order of a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

Microsoft September 2026 Patch Tuesday Fixes 973 Vulnerabilities and 2 Exploited Zero-Days

Microsoft's September 2026 Patch Tuesday fixes 973 vulnerabilities, including two zero-days already exploited in the wild.

Microsoft's September 2026 Patch Tuesday addresses 973 vulnerabilities across Windows, Office, and Azure components, including two zero-days already exploited in the wild. CVE-2026-81963, an elevation of privilege flaw in the Windows Update Stack, is flagged as an exploited zero-day. The release includes numerous remote code execution and information disclosure fixes for Microsoft Excel and Word, plus patches for the Windows kernel, ALPC, Print Spooler, ReFS, Entra ID, and Azure CLI.

GBHackers · 6d agoAdvisory in the wildCVE-2026-85880CVE-2026-85877CVE-2026-85875+27 CVEs