ZeroHour

CVE-2026-83988

mass1

Heap-Based Overflow in Windows Biometric Service Enables Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-83988 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, a component that Microsoft patched as part of its September 2026 Patch Tuesday release covering 973 vulnerabilities. The flaw can be triggered by a local, low-privileged authorized user interacting with the biometric service, with no user interaction required and low attack complexity. Successful exploitation lets the attacker elevate privileges locally, gaining high impact on confidentiality, integrity, and availability of the host, which is reflected in the 7.8 (high) CVSS 3.1 score. Any Windows system running the Windows Biometric Service is affected, though the provided data does not enumerate specific Windows version ranges. As of this writing there is no public proof-of-concept, the CVE is not in CISA's KEV, and EPSS estimates only about a 0.3% probability of exploitation within 30 days; the September release included two actively exploited zero-days, but no confirmed in-the-wild exploitation of this specific CVE is documented.

What to do: Apply Microsoft's September 2026 Windows security updates promptly, prioritizing shared workstations, VDI hosts, and kiosk systems where low-privileged users can log on. Until patching is complete, restrict local logon rights to trusted users and consider stopping the Windows Biometric Service (WbioSrvc) on systems that do not use Windows Hello or biometric sign-in. Consult Microsoft's September 2026 advisory for the exact affected builds, since version ranges are not included in this data.

Affected
Microsoft Windows (Windows Biometric Service component)
Estimated exposure
mass>1 billion Windows endpoints (WBS is a built-in Windows OS component) — Windows runs on well over a billion active devices worldwide and the Biometric Service ships as a default OS component, so the vulnerable code is present on effectively every Windows installation, although exploitation requires local…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

Microsoft September 2026 Patch Tuesday Fixes 973 Vulnerabilities and 2 Exploited Zero-Days

Microsoft's September 2026 Patch Tuesday fixes 973 vulnerabilities, including two zero-days already exploited in the wild.

Microsoft's September 2026 Patch Tuesday addresses 973 vulnerabilities across Windows, Office, and Azure components, including two zero-days already exploited in the wild. CVE-2026-81963, an elevation of privilege flaw in the Windows Update Stack, is flagged as an exploited zero-day. The release includes numerous remote code execution and information disclosure fixes for Microsoft Excel and Word, plus patches for the Windows kernel, ALPC, Print Spooler, ReFS, Entra ID, and Azure CLI.

GBHackers · 6d agoAdvisory in the wildCVE-2026-85880CVE-2026-85877CVE-2026-85875+27 CVEs