Junglewise Threat Intelligence

CVE-2026-83975: Microsoft Windows Biometric Service heap buffer overflow

CVE-2026-83975 · Severity: high · CVSS 7.8 · Published 2026-09-08

Executive brief

Windows Biometric Service is a Windows system component that processes fingerprint and other biometric authentication data. A heap buffer overflow vulnerability allows an authorized local attacker to execute arbitrary code and elevate their privileges to system level, potentially gaining complete control of the affected computer.

Technical details

A heap-based buffer overflow exists in the Windows Biometric Service that can be triggered by an authenticated local attacker. The vulnerability requires prior authentication and local access to the system. Successful exploitation allows an attacker to overwrite heap memory structures and execute arbitrary code with elevated privileges, achieving privilege escalation from a standard user account to SYSTEM level. The vulnerability has been assigned CVE-2026-83975 with a CVSS score of 7.8, indicating high severity.

Affected products

  • Microsoft Windows Biometric Service

Timeline

  • 2026-09-08: disclosed

References

Related threats