ZeroHour

CVE-2026-83977

mass

Heap Buffer Overflow in Windows Biometric Service Allows Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p24
Published
()
Modified
AI analysis

CVE-2026-83977 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, the component that manages fingerprint, face, and other biometric sign-in data. A local attacker who already holds a low-privileged account on a target machine can trigger the overflow by feeding crafted data to the service; the attack requires no user interaction and can succeed unattended. Successful exploitation grants the attacker elevated privileges with high impact on confidentiality, integrity, and availability on the compromised host. Affected releases span Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2 through 26H1), and Windows Server 2016 through 2025. As of this analysis there is no known exploitation, no public proof-of-concept, and the flaw is not in CISA's KEV catalog; it was addressed in Microsoft's September 2026 Patch Tuesday (973 vulnerabilities fixed), and is not reported as one of the two exploited zero-days.

What to do: Apply Microsoft's September 2026 security updates (the current cumulative update for each affected release) across Windows 10 1607/1809/21H2/22H2, Windows 11 23H2-26H1, and Windows Server 2016-2025. Until patched, limit local account access on shared or multi-user machines and prioritize endpoints where Windows Hello or fingerprint sign-in is enabled. With no known exploitation, no public PoC, and a low EPSS score (~0.3%), routine patch-cadence remediation is sufficient, but verify the update applied cleanly on biometric-enabled hosts.

Affected
Microsoft Windows 101607
Microsoft Windows 101809
Microsoft Windows 1021H2
Microsoft Windows 1022H2
Microsoft Windows 1123H2
Microsoft Windows 1124H2
Microsoft Windows 1125H2
Microsoft Windows 1126H1
Microsoft Windows Server2016
Microsoft Windows Server2019
Microsoft Windows Server2022
Microsoft Windows Server2025
Estimated exposure
masshundreds of millions to >1 billion Windows installations (Windows 10/11 desktop installed base plus Windows Server fleets) — Windows 10 and 11 run on well over a billion devices worldwide according to Microsoft's public figures, and the listed releases plus Windows Server 2016-2025 cover essentially the entire installed base, on all of which the Biometric…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

Microsoft September 2026 Patch Tuesday Fixes 973 Vulnerabilities and 2 Exploited Zero-Days

Microsoft's September 2026 Patch Tuesday fixes 973 vulnerabilities, including two zero-days already exploited in the wild.

Microsoft's September 2026 Patch Tuesday addresses 973 vulnerabilities across Windows, Office, and Azure components, including two zero-days already exploited in the wild. CVE-2026-81963, an elevation of privilege flaw in the Windows Update Stack, is flagged as an exploited zero-day. The release includes numerous remote code execution and information disclosure fixes for Microsoft Excel and Word, plus patches for the Windows kernel, ALPC, Print Spooler, ReFS, Entra ID, and Azure CLI.

GBHackers · 6d agoAdvisory in the wildCVE-2026-85880CVE-2026-85877CVE-2026-85875+27 CVEs