Junglewise Threat Intelligence

CVE-2026-83980: Microsoft Windows Biometric Service heap-based buffer overflow

CVE-2026-83980 · Severity: high · CVSS 7.8 · Published 2026-09-08

Executive brief

Windows Biometric Service is a core Windows system component responsible for fingerprint and facial recognition authentication. A heap-based buffer overflow in this service allows an authenticated local user to execute code with elevated privileges, potentially gaining full control of the system.

Technical details

A heap-based buffer overflow vulnerability exists in the Windows Biometric Service when processing biometric input data. The vulnerability requires an authenticated local attacker with user-level privileges to exploit. By providing specially crafted biometric data or parameters to the service, an attacker can overflow a heap buffer and achieve arbitrary code execution in the context of the LocalSystem account, leading to complete privilege escalation. Microsoft has released security patches to address this issue.

Affected products

  • Microsoft Windows Biometric Service

Timeline

  • 2026-09-08: disclosed

References

Related threats