AI analysis
CVE-2026-83978 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, the built-in component that handles fingerprint, face, and other biometric authentication on Windows. An attacker who already has a standard (low-privileged) account on the machine can trigger the flaw locally, with no user interaction required, causing memory corruption in the service. Successful exploitation allows the attacker to elevate privileges on the local host, gaining high confidentiality, integrity, and availability impact — a classic local privilege escalation to administrative/SYSTEM-level access. Anyone running the affected Windows 10 (1607, 1809, 21H2, 22H2) and Windows 11 (23H2, 24H2, 25H2, 26H1) client builds, or Windows Server 2016, 2019, 2022, or 2025, is in scope, and because the Biometric Service ships with Windows by default the exposure spans essentially the entire installed base on those branches. As of the September 2026 Patch Tuesday release (which fixed 973 vulnerabilities and two other actively exploited zero-days), no public proof-of-concept is known, the flaw is not in CISA's KEV catalog, and its EPSS of 0.3% (25th percentile) points to low near-term exploitation risk.
What to do: Apply Microsoft's September 2026 security updates (cumulative updates) for every affected Windows 10/11 client version and Windows Server version listed above, as no public PoC or workaround is known. Prioritize hosts where multiple low-privileged users log on locally — shared workstations, kiosks, RDS/VDI servers, and admin jump boxes — and verify the update is installed on all Windows Server builds in the estate.
Affected
| Microsoft Windows 10 1607 | 1607 |
| Microsoft Windows 10 1809 | 1809 |
| Microsoft Windows 10 21H2 | 21H2 |
| Microsoft Windows 10 22H2 | 22H2 |
| Microsoft Windows 11 23H2 | 23H2 |
| Microsoft Windows 11 24H2 | 24H2 |
| Microsoft Windows 11 25H2 | 25H2 |
| Microsoft Windows 11 26H1 | 26H1 |
| Microsoft Windows Server 2016 | 2016 |
| Microsoft Windows Server 2019 | 2019 |
| Microsoft Windows Server 2022 | 2022 |
| Microsoft Windows Server 2025 | 2025 |
Estimated exposure
masshundreds of millions of Windows endpoints (a subset of Microsoft's reported ~1.4B+ active Windows 10/11 devices, plus enterprise Windows Server fleets) — The Windows Biometric Service is present by default on every affected client and server release, so exposure is effectively the entire installed base of Windows 10/11 and the listed Windows Server versions, which Microsoft pegs at well…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.