ZeroHour

CVE-2026-83983

mass

Local Privilege Escalation via Heap Buffer Overflow in Windows Biometric Service

CVSS 3.1
7.8 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-83983 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, the Windows component that brokers biometric logon (e.g., Windows Hello, fingerprint and facial-recognition authentication). An attacker who already holds a low-privileged, authorized account on a vulnerable Windows machine can trigger the overflow locally without user interaction, corrupting memory in the service. Successful exploitation allows the attacker to elevate privileges on the local system, with high impact to the confidentiality, integrity, and availability of the host (CVSS 3.1: 7.8, AV:L/PR:L/UI:N). Any Windows deployment running an affected build of the Biometric Service is exposed; the provided data does not enumerate specific affected Windows versions, so defenders should consult Microsoft's advisory for the exact build ranges. Exploitation is not currently confirmed: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS puts 30-day exploitation probability at only 0.3% (25th percentile), although related reporting ties Microsoft's September 2026 Patch Tuesday (973 vulnerabilities fixed, including two separately exploited zero-days) to this fix cycle.

What to do: Apply Microsoft's September 2026 (or later) cumulative Windows updates across the fleet, prioritizing multi-user workstations, kiosks, and shared endpoints where local privilege escalation has the greatest impact; the data does not list specific affected KBs or builds, so confirm applicability and fixed builds on Microsoft's advisory for CVE-2026-83983. Since exploitation is unconfirmed and requires local access, no emergency mitigation is required, but until patching, restrict untrusted local users from running code on sensitive Windows hosts.

Affected
Microsoft Windows Biometric Service (Windows)
Estimated exposure
masson the order of hundreds of millions of Windows endpoints (Windows runs on well over a billion devices; the Biometric Service is a default Windows component) — Based on Microsoft's publicly stated installed base of 1+ billion active Windows devices and the fact that the Windows Biometric Service ships by default with modern Windows client editions, with the true count somewhat reduced because the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

Microsoft September 2026 Patch Tuesday Fixes 973 Vulnerabilities and 2 Exploited Zero-Days

Microsoft's September 2026 Patch Tuesday fixes 973 vulnerabilities, including two zero-days already exploited in the wild.

Microsoft's September 2026 Patch Tuesday addresses 973 vulnerabilities across Windows, Office, and Azure components, including two zero-days already exploited in the wild. CVE-2026-81963, an elevation of privilege flaw in the Windows Update Stack, is flagged as an exploited zero-day. The release includes numerous remote code execution and information disclosure fixes for Microsoft Excel and Word, plus patches for the Windows kernel, ALPC, Print Spooler, ReFS, Entra ID, and Azure CLI.

GBHackers · 7d agoAdvisory in the wildCVE-2026-85880CVE-2026-85877CVE-2026-85875+27 CVEs1