Junglewise Threat Intelligence

CVE-2026-83971: Microsoft Windows Biometric Service heap buffer overflow

CVE-2026-83971 · Severity: high · CVSS 7.8 · Published 2026-09-08

Executive brief

Windows Biometric Service is a system component that manages fingerprint and facial recognition authentication on Windows computers. A heap buffer overflow vulnerability in this service allows a user with local access to execute arbitrary code with elevated system privileges, potentially leading to complete compromise of the affected computer.

Technical details

A heap-based buffer overflow exists in the Windows Biometric Service, a core Windows component responsible for processing biometric authentication data. The vulnerability requires an authenticated attacker with local access to trigger the overflow condition. Exploitation allows arbitrary code execution with privileges higher than the attacker's current user context, enabling privilege escalation. The attack vector is local-only and requires prior authentication or interactive access to the system. A patch has been released by Microsoft as part of their security update process.

Affected products

  • Microsoft Windows Biometric Service <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats