Heap-Based Buffer Overflow in Windows Biometric Service by Microsoft
CVE-2026-83954
7.8HIGH
Key Information:
- Vendor
Microsoft
- Vendor
- CVE Published:
- 8 September 2026
What is CVE-2026-83954?
A vulnerability in the Windows Biometric Service has been identified that allows an authorized attacker to execute a heap-based buffer overflow. This could enable the attacker to elevate privileges on the affected system locally. It is crucial for users to apply the recommended security patches to mitigate the risk associated with this vulnerability.
Affected Version(s)
Windows 10 Version 1607 32-bit Systems 10.0.14393.0 < 10.0.14393.9512
Windows 10 Version 1809 32-bit Systems 10.0.17763.0 < 10.0.17763.9245
Windows 10 Version 21H2 32-bit Systems 10.0.19044.0 < 10.0.19044.7725