ZeroHour

CVE-2026-83979

mass

Use-After-Free Privilege Escalation in Windows Biometric Service

CVSS 3.1
7.8 high
EPSS
<1%p24
Published
()
Modified
AI analysis

CVE-2026-83979 is a use-after-free flaw (CWE-416) in the Windows Biometric Service, the component that handles fingerprint, facial, and other biometric authentication on Windows. An attacker who is already authorized on the machine with low privileges can trigger the bug, presumably by sending crafted input to the service that causes memory to be used after it has been freed. Successful exploitation allows local elevation of privileges, with high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.8, AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). The affected range spans mainstream Windows 10 and Windows 11 client releases plus Windows Server 2016 through 2025, covering nearly the entire currently supported Windows estate. As of the September 2026 Patch Tuesday disclosure there is no CISA KEV listing, no known public proof-of-concept, and EPSS estimates only a 0.3% chance of exploitation within 30 days; the flaw is not identified as one of the two zero-days actively exploited that month.

What to do: Apply Microsoft's September 2026 security updates to all affected Windows 10/11 clients and Windows Server hosts, prioritizing multi-user endpoints, shared workstations, and remote machines where untrusted users hold local sign-in rights. Because exploitation requires a local low-privileged foothold, review and restrict which accounts can log on interactively to servers in the meantime. Where Windows Hello or biometric sign-in is not used, disabling the Windows Biometric Service is a reasonable interim risk reduction pending patching.

Affected
Microsoft Windows 101607 (builds prior to the September 2026 security updates)
Microsoft Windows 101809 (builds prior to the September 2026 security updates)
Microsoft Windows 1021H2 (builds prior to the September 2026 security updates)
Microsoft Windows 1022H2 (builds prior to the September 2026 security updates)
Microsoft Windows 1123H2 (builds prior to the September 2026 security updates)
Microsoft Windows 1124H2 (builds prior to the September 2026 security updates)
Microsoft Windows 1125H2 (builds prior to the September 2026 security updates)
Microsoft Windows 1126H1 (builds prior to the September 2026 security updates)
Microsoft Windows Server 2016all supported builds prior to the September 2026 security updates
Microsoft Windows Server 2019all supported builds prior to the September 2026 security updates
Microsoft Windows Server 2022all supported builds prior to the September 2026 security updates
Microsoft Windows Server 2025all supported builds prior to the September 2026 security updates
Estimated exposure
mass≈ hundreds of millions of Windows devices (affected versions cover the mainstream Windows 10/11 client and Windows Server install base) — The listed versions span essentially the entire supported Windows ecosystem, which public market-share data places at well over a billion Windows devices, and the Windows Biometric Service is present by default on these releases; practical…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

Microsoft September 2026 Patch Tuesday Fixes 973 Vulnerabilities and 2 Exploited Zero-Days

Microsoft's September 2026 Patch Tuesday fixes 973 vulnerabilities, including two zero-days already exploited in the wild.

Microsoft's September 2026 Patch Tuesday addresses 973 vulnerabilities across Windows, Office, and Azure components, including two zero-days already exploited in the wild. CVE-2026-81963, an elevation of privilege flaw in the Windows Update Stack, is flagged as an exploited zero-day. The release includes numerous remote code execution and information disclosure fixes for Microsoft Excel and Word, plus patches for the Windows kernel, ALPC, Print Spooler, ReFS, Entra ID, and Azure CLI.

GBHackers · 6d agoAdvisory in the wildCVE-2026-85880CVE-2026-85877CVE-2026-85875+27 CVEs