Junglewise Threat Intelligence

CVE-2026-83955: Microsoft Windows Biometric Service heap buffer overflow

CVE-2026-83955 · Severity: high · CVSS 7.8 · Published 2026-09-08

Executive brief

Windows Biometric Service is a system component that manages fingerprint and other biometric authentication on Windows computers. A heap-based buffer overflow in this service allows an already-authorized local attacker to run arbitrary code with higher privileges, potentially taking full control of the affected machine.

Technical details

A heap-based buffer overflow exists in the Windows Biometric Service, allowing a local authenticated attacker to trigger memory corruption. The vulnerability requires local access and prior authorization to interact with the affected service. Successful exploitation permits privilege escalation, enabling the attacker to execute arbitrary code in the context of the Biometric Service with elevated privileges. A patch is available from Microsoft through the Security Update Guide.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed
  • 2026-09-08: advisory

References

Related threats