Heap Buffer Overflow in Windows Biometric Service Enables Local Privilege Escalation
AI analysis
CVE-2026-83980 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, a component present by default in Windows 10, Windows 11, and Windows Server. A local attacker who is already authorized on the machine (low privileges, no user interaction required) can trigger the overflow by sending crafted input to the service. Successful exploitation allows elevation of privileges on the local system with high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.8). All listed Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2 through 26H1), and Windows Server (2016 through 2025) releases are affected. The flaw is not currently known to be exploited — no public PoC, not in CISA KEV, and EPSS is 0.3% — and fixes shipped in Microsoft's September 2026 Patch Tuesday release (973 vulnerabilities fixed, including 2 exploited zero-days not attributed to this CVE).
What to do: Apply Microsoft's September 2026 cumulative security updates for all listed Windows 10, Windows 11, and Windows Server versions as soon as possible. As an interim measure on systems that do not use Windows Hello or biometric sign-in, consider disabling the Windows Biometric Service to reduce exposure. Prioritize patching multi-user hosts, terminal servers, and other machines where low-privileged local users can run code, and verify patch status against vendor advisories.
Affected
| Microsoft Windows 10 | 1607, 1809, 21H2, 22H2 |
| Microsoft Windows 11 | 23H2, 24H2, 25H2, 26H1 |
| Microsoft Windows Server | 2016, 2019, 2022, 2025 |
Estimated exposure
masshundreds of millions of Windows 10/11 and Windows Server installations (Windows 10/11 install base exceeds 1 billion devices) — The Windows Biometric Service ships by default across all listed Windows client and server releases, so exposure is effectively the install base of those versions — hundreds of millions of devices, given the Windows 10/11 install base of…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.