ZeroHour

CVE-2026-83985

mass

Heap Buffer Overflow in Windows Biometric Service Enables Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p24
Published
()
Modified
AI analysis

CVE-2026-83985 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service (WbioSrvc) on supported Windows 10, Windows 11, and Windows Server releases. A local, already-authenticated user with low privileges and no user interaction can trigger the overflow via a crafted request or operation handled by the service. Successful exploitation yields elevated privileges on the local host, with high impact on confidentiality, integrity, and availability — effectively a full local compromise. Any organization or individual running the listed Windows 10/11 client versions or Windows Server 2016–2025 is exposed, though exploitation requires local code execution first. The flaw is not in CISA KEV, has no known public PoC, a modest 0.3% EPSS, and is believed unexploited; it was addressed in Microsoft's September 2026 Patch Tuesday release, which fixed 973 vulnerabilities (two of them already-exploited zero-days, though not this one).

What to do: Apply Microsoft's September 2026 cumulative updates for each affected Windows 10/11 and Windows Server version; verify patch rollout across client fleets, servers, and LTSC/long-term servicing branches such as 1607 and 1809. No workaround is documented, but prioritize hosts where multiple untrusted users can log on locally and audit which machines use Windows Hello biometrics. Patch all systems running the listed versions, including those without biometric hardware, since the service is present by default.

Affected
microsoft Windows 101607, 1809, 21H2, 22H2
microsoft Windows 1123H2, 24H2, 25H2, 26H1
microsoft Windows Server2016, 2019, 2022, 2025
Estimated exposure
masshundreds of millions of Windows 10/11/Server installations carry the vulnerable service (Windows installed base ≈1B+ devices; actively used biometrics are a… — The Biometric Service ships by default on all listed Windows 10/11 and Windows Server releases, whose combined installed base is on the order of a billion devices, though only systems with enrolled Windows Hello biometrics actively use the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

Microsoft September 2026 Patch Tuesday Fixes 973 Vulnerabilities and 2 Exploited Zero-Days

Microsoft's September 2026 Patch Tuesday fixes 973 vulnerabilities, including two zero-days already exploited in the wild.

Microsoft's September 2026 Patch Tuesday addresses 973 vulnerabilities across Windows, Office, and Azure components, including two zero-days already exploited in the wild. CVE-2026-81963, an elevation of privilege flaw in the Windows Update Stack, is flagged as an exploited zero-day. The release includes numerous remote code execution and information disclosure fixes for Microsoft Excel and Word, plus patches for the Windows kernel, ALPC, Print Spooler, ReFS, Entra ID, and Azure CLI.

GBHackers · 7d agoAdvisory in the wildCVE-2026-85880CVE-2026-85877CVE-2026-85875+27 CVEs