ZeroHour

CVE-2026-83981

mass

Heap Buffer Overflow in Windows Biometric Service Enables Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p24
Published
()
Modified
AI analysis

CVE-2026-83981 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, addressed by Microsoft in its September 2026 Patch Tuesday release. An authorized local attacker with low privileges can trigger the overflow through the biometric service without any user interaction, corrupting heap memory. Successful exploitation allows the attacker to elevate privileges locally, with the CVSS scoring high impact on confidentiality, integrity, and availability (7.8 High). The flaw affects essentially all currently serviced Windows client lines (Windows 10 1607/1809/21H2/22H2 and Windows 11 23H2/24H2/25H2/26H1) as well as Windows Server 2016 through 2025. There is no public proof-of-concept, the CVE is not in CISA's KEV catalog, and EPSS estimates only about a 0.3% chance of exploitation in the next 30 days.

What to do: Deploy the September 2026 Windows security updates from Microsoft for all listed Windows 10 and Windows 11 client builds and Windows Server 2016/2019/2022/2025. Prioritize endpoints where users authenticate with Windows Hello fingerprint or facial recognition, since the Biometric Service is actively exercised there; verify via the Windows Update or WSUS patch-compliance reports that all listed builds have received the September 2026 cumulative update. No workarounds or exploited-in-the-wild activity are reported, but the low attack complexity and no-user-interaction vector make this a routine patch-first item rather than an emergency.

Affected
microsoft Windows 101607
microsoft Windows 101809
microsoft Windows 1021H2
microsoft Windows 1022H2
microsoft Windows 1123H2
microsoft Windows 1124H2
microsoft Windows 1125H2
microsoft Windows 1126H1
microsoft Windows Server 2016as listed in the September 2026 advisory
microsoft Windows Server 2019as listed in the September 2026 advisory
microsoft Windows Server 2022as listed in the September 2026 advisory
microsoft Windows Server 2025as listed in the September 2026 advisory
Estimated exposure
masshundreds of millions of Windows devices potentially in scope (Windows 10/11 installed base exceeds 1 billion; the Biometric Service is present by default,… — The affected versions span the entire supported Windows client and server installed base (over a billion Windows devices per public market data), so exposure is mass by deployment share, tempered by the local attack vector and the need for…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

Microsoft September 2026 Patch Tuesday Fixes 973 Vulnerabilities and 2 Exploited Zero-Days

Microsoft's September 2026 Patch Tuesday fixes 973 vulnerabilities, including two zero-days already exploited in the wild.

Microsoft's September 2026 Patch Tuesday addresses 973 vulnerabilities across Windows, Office, and Azure components, including two zero-days already exploited in the wild. CVE-2026-81963, an elevation of privilege flaw in the Windows Update Stack, is flagged as an exploited zero-day. The release includes numerous remote code execution and information disclosure fixes for Microsoft Excel and Word, plus patches for the Windows kernel, ALPC, Print Spooler, ReFS, Entra ID, and Azure CLI.

GBHackers · 6d agoAdvisory in the wildCVE-2026-85880CVE-2026-85877CVE-2026-85875+27 CVEs