Junglewise Threat Intelligence

CVE-2026-83977: Microsoft Windows Biometric Service heap buffer overflow

CVE-2026-83977 · Severity: high · CVSS 7.8 · Published 2026-09-08

Executive brief

Windows Biometric Service, a system component that processes fingerprint and other biometric authentication data, contains a heap-based buffer overflow vulnerability. An authorized local user can exploit this flaw to execute arbitrary code with elevated system privileges, potentially compromising the entire system.

Technical details

A heap-based buffer overflow exists in the Windows Biometric Service that allows an authenticated local attacker to write beyond allocated memory boundaries. The vulnerability requires local access and prior authentication, but does not require user interaction. Successful exploitation enables privilege escalation from a standard user context to SYSTEM or Administrator level, granting complete control over the affected system. A patch is available from Microsoft.

Affected products

  • Microsoft Windows Biometric Service <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats