ZeroHour

CVE-2026-83980

mass

Heap Buffer Overflow in Windows Biometric Service Enables Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p24
Published
()
Modified
AI analysis

CVE-2026-83980 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, a component present by default in Windows 10, Windows 11, and Windows Server. A local attacker who is already authorized on the machine (low privileges, no user interaction required) can trigger the overflow by sending crafted input to the service. Successful exploitation allows elevation of privileges on the local system with high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.8). All listed Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2 through 26H1), and Windows Server (2016 through 2025) releases are affected. The flaw is not currently known to be exploited — no public PoC, not in CISA KEV, and EPSS is 0.3% — and fixes shipped in Microsoft's September 2026 Patch Tuesday release (973 vulnerabilities fixed, including 2 exploited zero-days not attributed to this CVE).

What to do: Apply Microsoft's September 2026 cumulative security updates for all listed Windows 10, Windows 11, and Windows Server versions as soon as possible. As an interim measure on systems that do not use Windows Hello or biometric sign-in, consider disabling the Windows Biometric Service to reduce exposure. Prioritize patching multi-user hosts, terminal servers, and other machines where low-privileged local users can run code, and verify patch status against vendor advisories.

Affected
Microsoft Windows 101607, 1809, 21H2, 22H2
Microsoft Windows 1123H2, 24H2, 25H2, 26H1
Microsoft Windows Server2016, 2019, 2022, 2025
Estimated exposure
masshundreds of millions of Windows 10/11 and Windows Server installations (Windows 10/11 install base exceeds 1 billion devices) — The Windows Biometric Service ships by default across all listed Windows client and server releases, so exposure is effectively the install base of those versions — hundreds of millions of devices, given the Windows 10/11 install base of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

Microsoft September 2026 Patch Tuesday Fixes 973 Vulnerabilities and 2 Exploited Zero-Days

Microsoft's September 2026 Patch Tuesday fixes 973 vulnerabilities, including two zero-days already exploited in the wild.

Microsoft's September 2026 Patch Tuesday addresses 973 vulnerabilities across Windows, Office, and Azure components, including two zero-days already exploited in the wild. CVE-2026-81963, an elevation of privilege flaw in the Windows Update Stack, is flagged as an exploited zero-day. The release includes numerous remote code execution and information disclosure fixes for Microsoft Excel and Word, plus patches for the Windows kernel, ALPC, Print Spooler, ReFS, Entra ID, and Azure CLI.

GBHackers · 6d agoAdvisory in the wildCVE-2026-85880CVE-2026-85877CVE-2026-85875+27 CVEs