Executive brief
Windows Biometric Service is a system component that handles fingerprint and other biometric authentication. A heap overflow vulnerability allows an authorized local user to crash the service or execute code with elevated privileges, potentially gaining full control of the computer.
Technical details
A heap-based buffer overflow exists in the Windows Biometric Service, allowing an authorized local attacker to overflow a heap buffer through a crafted input or request. The vulnerability requires the attacker to already have local authentication credentials. Successful exploitation permits privilege escalation from a standard user context to a higher privilege level (likely SYSTEM). The attack vector is local and requires user interaction or preconditioned access; remote exploitation is not possible via this vector. Microsoft has released a security patch to remediate this vulnerability.
Affected products
- Microsoft Windows Multiple versions (details in MSRC advisory)
Timeline
- 2026-09-08: disclosed
- other: CVE-2026-83974 identifier assigned