ZeroHour

CVE-2026-83978

mass1

Local Privilege Elevation via Heap Buffer Overflow in Windows Biometric Service

CVSS 3.1
7.8 high
EPSS
<1%p24
Published
()
Modified
AI analysis

CVE-2026-83978 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, the built-in component that handles fingerprint, face, and other biometric authentication on Windows. An attacker who already has a standard (low-privileged) account on the machine can trigger the flaw locally, with no user interaction required, causing memory corruption in the service. Successful exploitation allows the attacker to elevate privileges on the local host, gaining high confidentiality, integrity, and availability impact — a classic local privilege escalation to administrative/SYSTEM-level access. Anyone running the affected Windows 10 (1607, 1809, 21H2, 22H2) and Windows 11 (23H2, 24H2, 25H2, 26H1) client builds, or Windows Server 2016, 2019, 2022, or 2025, is in scope, and because the Biometric Service ships with Windows by default the exposure spans essentially the entire installed base on those branches. As of the September 2026 Patch Tuesday release (which fixed 973 vulnerabilities and two other actively exploited zero-days), no public proof-of-concept is known, the flaw is not in CISA's KEV catalog, and its EPSS of 0.3% (25th percentile) points to low near-term exploitation risk.

What to do: Apply Microsoft's September 2026 security updates (cumulative updates) for every affected Windows 10/11 client version and Windows Server version listed above, as no public PoC or workaround is known. Prioritize hosts where multiple low-privileged users log on locally — shared workstations, kiosks, RDS/VDI servers, and admin jump boxes — and verify the update is installed on all Windows Server builds in the estate.

Affected
Microsoft Windows 10 16071607
Microsoft Windows 10 18091809
Microsoft Windows 10 21H221H2
Microsoft Windows 10 22H222H2
Microsoft Windows 11 23H223H2
Microsoft Windows 11 24H224H2
Microsoft Windows 11 25H225H2
Microsoft Windows 11 26H126H1
Microsoft Windows Server 20162016
Microsoft Windows Server 20192019
Microsoft Windows Server 20222022
Microsoft Windows Server 20252025
Estimated exposure
masshundreds of millions of Windows endpoints (a subset of Microsoft's reported ~1.4B+ active Windows 10/11 devices, plus enterprise Windows Server fleets) — The Windows Biometric Service is present by default on every affected client and server release, so exposure is effectively the entire installed base of Windows 10/11 and the listed Windows Server versions, which Microsoft pegs at well…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

Microsoft September 2026 Patch Tuesday Fixes 973 Vulnerabilities and 2 Exploited Zero-Days

Microsoft's September 2026 Patch Tuesday fixes 973 vulnerabilities, including two zero-days already exploited in the wild.

Microsoft's September 2026 Patch Tuesday addresses 973 vulnerabilities across Windows, Office, and Azure components, including two zero-days already exploited in the wild. CVE-2026-81963, an elevation of privilege flaw in the Windows Update Stack, is flagged as an exploited zero-day. The release includes numerous remote code execution and information disclosure fixes for Microsoft Excel and Word, plus patches for the Windows kernel, ALPC, Print Spooler, ReFS, Entra ID, and Azure CLI.

GBHackers · 7d agoAdvisory in the wildCVE-2026-85880CVE-2026-85877CVE-2026-85875+27 CVEs