Junglewise Threat Intelligence

CVE-2026-83972: Microsoft Windows Biometric Service heap buffer overflow

CVE-2026-83972 · Severity: high · CVSS 7.8 · Published 2026-09-08

Executive brief

Windows Biometric Service is a core Windows component that processes biometric authentication data such as fingerprints and facial recognition. A heap buffer overflow vulnerability in this service allows an authorized local user to crash the service or execute arbitrary code with elevated system privileges, potentially compromising the entire system.

Technical details

A heap-based buffer overflow exists in Microsoft Windows Biometric Service that can be triggered by an authenticated local attacker. The vulnerability allows an attacker with local system access to overflow a heap buffer, potentially leading to denial of service or arbitrary code execution with elevated privileges. The attack requires local access and authenticated user context. A patch has been released by Microsoft as indicated by the MSRC guidance link.

Affected products

  • Microsoft Windows Biometric Service <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats