ZeroHour

CVE-2026-83976

mass

Local Privilege Escalation via Heap Buffer Overflow in Windows Biometric Service

CVSS 3.1
7.8 high
EPSS
<1%p15
Published
()
Modified
AI analysis

CVE-2026-83976 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service affecting Windows 10, Windows 11, and Windows Server. A local, authenticated (low-privileged) user can trigger the overflow by sending crafted input to the service, corrupting heap memory and executing code in the service's security context. Successful exploitation allows the attacker to elevate privileges on the local machine, with high impact on confidentiality, integrity, and availability per the CVSS 7.8 score; no user interaction or remote access is required beyond an existing local session. All listed Windows client builds (Windows 10 1607 through Windows 11 26H1) and Windows Server 2016 through 2025 are affected, with the greatest practical exposure on machines equipped with Windows Hello fingerprint or face authentication hardware. No public proof of concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, and EPSS estimates only a 0.2% probability of exploitation within 30 days; Microsoft's September 2026 Patch Tuesday fixed 973 vulnerabilities including two exploited zero-days, but this flaw is not confirmed to be among them.

What to do: Apply Microsoft's September 2026 security updates on all affected Windows 10, Windows 11, and Windows Server builds via Windows Update, WSUS, or your patch management platform, prioritizing shared or multi-user machines (kiosks, shared workstations) and devices with Windows Hello sensors. Inventory endpoints for the listed builds and confirm the patch is installed; no public PoC or workaround is known, so patching is the primary remediation.

Affected
microsoft Windows 101607, 1809, 21H2, 22H2
microsoft Windows 1123H2, 24H2, 25H2, 26H1
microsoft Windows Server2016, 2019, 2022, 2025
Estimated exposure
masshundreds of millions of Windows client and server installations (Biometric Service ships by default on all listed versions) — Windows 10 and 11 run on well over a billion active devices and the Windows Biometric Service is present by default on every listed client and server version, with practical exploitability concentrated on systems with Windows Hello…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

Microsoft September 2026 Patch Tuesday Fixes 973 Vulnerabilities and 2 Exploited Zero-Days

Microsoft's September 2026 Patch Tuesday fixes 973 vulnerabilities, including two zero-days already exploited in the wild.

Microsoft's September 2026 Patch Tuesday addresses 973 vulnerabilities across Windows, Office, and Azure components, including two zero-days already exploited in the wild. CVE-2026-81963, an elevation of privilege flaw in the Windows Update Stack, is flagged as an exploited zero-day. The release includes numerous remote code execution and information disclosure fixes for Microsoft Excel and Word, plus patches for the Windows kernel, ALPC, Print Spooler, ReFS, Entra ID, and Azure CLI.

GBHackers · 7d agoAdvisory in the wildCVE-2026-85880CVE-2026-85877CVE-2026-85875+27 CVEs