Junglewise Threat Intelligence

CVE-2026-83978: Microsoft Windows Biometric Service heap overflow privilege escalation

CVE-2026-83978 · Severity: high · CVSS 7.8 · Published 2026-09-08

Executive brief

Windows Biometric Service is a system component that manages fingerprint and other biometric authentication on Windows devices. A heap buffer overflow in this service allows an authenticated attacker to execute code with elevated privileges, potentially gaining full control of an affected system and bypassing security protections.

Technical details

A heap-based buffer overflow vulnerability exists in the Windows Biometric Service that can be triggered by an authenticated local attacker. The vulnerability allows an attacker with local system access to overwrite heap memory, leading to arbitrary code execution with elevated privileges. Attack preconditions require the attacker to be authenticated and have local access to the system. Successful exploitation enables privilege escalation from user-level to system-level access. A patch is expected to be available from Microsoft.

Affected products

  • Microsoft Windows Biometric Service <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats