Junglewise Threat Intelligence

CVE-2026-83986: Microsoft Windows Biometric Service heap-based buffer overflow

CVE-2026-83986 · Severity: high · CVSS 7.8 · Published 2026-09-08

Executive brief

Windows Biometric Service, a component used for fingerprint and other biometric authentication on Windows systems, contains a heap memory corruption vulnerability. An authenticated local attacker can exploit this flaw to gain elevated system privileges, potentially compromising the entire Windows system and all user data on it.

Technical details

A heap-based buffer overflow exists in Microsoft Windows Biometric Service that can be triggered by an authorized local attacker. The vulnerability allows an attacker with local access and valid credentials to overflow a heap buffer, leading to arbitrary code execution and privilege escalation. The attack requires local system access and valid user authentication; it cannot be exploited remotely over the network. Successful exploitation grants the attacker SYSTEM-level privileges. A patch is expected from Microsoft as part of regular security updates.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats