ZeroHour

CVE-2026-83982

mass

Heap Buffer Overflow in Windows Biometric Service Enables Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p24
Published
()
Modified
AI analysis

CVE-2026-83982 is a heap-based buffer overflow (CWE-122) in the Microsoft Windows Biometric Service, rated 7.8 (High) on CVSS 3.1 for local privilege escalation. A local, low-privileged ('authorized') user can trigger the overflow by getting the service to mishandle crafted input, with no user interaction required. Successful exploitation yields code execution in the service's elevated context, giving the attacker higher privileges on the local host with high impact on confidentiality, integrity, and availability. All unpatched installations of the listed Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2, 26H1), and Windows Server (2016, 2019, 2022, 2025) releases are affected. No public proof-of-concept or in-the-wild exploitation is known: EPSS is 0.3% (25th percentile), it is not in CISA KEV, and it is not one of the two zero-days Microsoft reported as actively exploited in its September 2026 Patch Tuesday release.

What to do: Apply Microsoft's September 2026 security updates (or later) across all listed Windows 10, Windows 11, and Windows Server systems, and verify hosts are on a patched build per Microsoft's advisory. Prioritize systems where untrusted or unprivileged users log on interactively - VDI, kiosks, shared workstations, and RDS/terminal servers - since exploitation requires only an authenticated local account. With no public PoC or known exploitation, routine patch cadence is acceptable, but do not defer on multi-user hosts.

Affected
Microsoft Windows 101607, 1809, 21H2, 22H2
Microsoft Windows 1123H2, 24H2, 25H2, 26H1
Microsoft Windows Server2016, 2019, 2022, 2025
Estimated exposure
masshundreds of millions to ~1 billion+ Windows endpoints plus millions of Windows Server instances (all unpatched installs of the listed releases) — The vulnerable Biometric Service ships by default in every listed Windows release, Windows 10/11 account for roughly 70% of a global Windows install base above 1 billion devices, and Windows Server 2016-2025 is pervasive in enterprise data…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

Microsoft September 2026 Patch Tuesday Fixes 973 Vulnerabilities and 2 Exploited Zero-Days

Microsoft's September 2026 Patch Tuesday fixes 973 vulnerabilities, including two zero-days already exploited in the wild.

Microsoft's September 2026 Patch Tuesday addresses 973 vulnerabilities across Windows, Office, and Azure components, including two zero-days already exploited in the wild. CVE-2026-81963, an elevation of privilege flaw in the Windows Update Stack, is flagged as an exploited zero-day. The release includes numerous remote code execution and information disclosure fixes for Microsoft Excel and Word, plus patches for the Windows kernel, ALPC, Print Spooler, ReFS, Entra ID, and Azure CLI.

GBHackers · 7d agoAdvisory in the wildCVE-2026-85880CVE-2026-85877CVE-2026-85875+27 CVEs