Heap-Based Overflow in Windows Biometric Service Enables Local Privilege Escalation
AI analysis
CVE-2026-83988 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, a component that Microsoft patched as part of its September 2026 Patch Tuesday release covering 973 vulnerabilities. The flaw can be triggered by a local, low-privileged authorized user interacting with the biometric service, with no user interaction required and low attack complexity. Successful exploitation lets the attacker elevate privileges locally, gaining high impact on confidentiality, integrity, and availability of the host, which is reflected in the 7.8 (high) CVSS 3.1 score. Any Windows system running the Windows Biometric Service is affected, though the provided data does not enumerate specific Windows version ranges. As of this writing there is no public proof-of-concept, the CVE is not in CISA's KEV, and EPSS estimates only about a 0.3% probability of exploitation within 30 days; the September release included two actively exploited zero-days, but no confirmed in-the-wild exploitation of this specific CVE is documented.
What to do: Apply Microsoft's September 2026 Windows security updates promptly, prioritizing shared workstations, VDI hosts, and kiosk systems where low-privileged users can log on. Until patching is complete, restrict local logon rights to trusted users and consider stopping the Windows Biometric Service (WbioSrvc) on systems that do not use Windows Hello or biometric sign-in. Consult Microsoft's September 2026 advisory for the exact affected builds, since version ranges are not included in this data.
Affected
| Microsoft Windows (Windows Biometric Service component) | — |
Estimated exposure
mass>1 billion Windows endpoints (WBS is a built-in Windows OS component) — Windows runs on well over a billion active devices worldwide and the Biometric Service ships as a default OS component, so the vulnerable code is present on effectively every Windows installation, although exploitation requires local…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.