CVE-2026-85880
Windows ALPC heap-based buffer overflow allows local privilege escalation (CVE-2026-85880)
CVE-2026-85880 is a heap-based buffer overflow in Windows ALPC. An authenticated local attacker can exploit it to elevate privileges, and it is recorded as actively exploited by CISA KEV and Microsoft. Patched Windows builds are available.
What happened
A heap-based buffer overflow in the Windows Advanced Local Procedure Call (ALPC) component allows an attacker who already has low-privileged local access to elevate to higher privileges on the system. The attack vector is local, needs no user interaction, and the CVSS 3.1 score is 7.8 (high), with high impact on confidentiality, integrity and availability.
CISA's Known Exploited Vulnerabilities catalog and Microsoft's Security Response Center record this vulnerability as actively exploited. Microsoft rates it Important. Because ALPC is a core Windows inter-process communication mechanism, any unpatched Windows 10 or Windows Server system in the affected build ranges should be treated as exposed to a working local privilege escalation technique.
Who is affected
Affected products and version ranges are:
- Windows 10 Version 1607, before 10.0.14393.9512
- Windows 10 Version 1809, before 10.0.17763.9245
- Windows 10 Version 21H2, before 10.0.19044.7725
- Windows 10 Version 22H2, before 10.0.19045.7725
- Windows Server 2012 and Server Core installation, before 6.2.9200.26349
- Windows Server 2012 R2 and Server Core installation, before 6.3.9600.23398
- Windows Server 2016 and Server Core installation, before 10.0.14393.9512
- Windows Server 2019 and Server Core installation, before 10.0.17763.9245
These are standard Windows desktop and server builds. The relevant devices include any that allow low-privileged local logon or execution, whether staff workstations, shared or lab machines, RDS hosts, or infrastructure servers with user logon rights.
What to do now
- Apply Microsoft's fixed builds from the September 2026 security update. Fixed OS builds are: Windows 10 1607 10.0.14393.9512 (KB5123099); Windows 10 1809 and Windows Server 2019 10.0.17763.9245 (KB5122876); Windows 10 21H2 10.0.19044.7725 and Windows 10 22H2 10.0.19045.7725 (KB5122878); Windows Server 2012 6.2.9200.26349 (KB5123065); Windows Server 2012 R2 6.3.9600.23398 (KB5123066); Windows Server 2016 10.0.14393.9512 (KB5123099); Windows Server 2022 10.0.20348.5622 (KB5122882).
- Prioritise systems where unprivileged local sign-in is permitted. CISA KEV gives a remediation due date of 2026-09-22 for this CVE.
- Microsoft's advisory does not list a workaround. While you deploy, enforce least privilege: remove unnecessary local logon rights, separate administrative accounts, and limit the ability of standard users to run untrusted code.
Beyond the patch
Patched systems close the door, but with an actively exploited local privilege escalation the question is what may already have happened on the endpoint before the update landed. Managed Detection & Response (MDR) provides telemetry to spot post-exploitation behaviour that typically follows local elevation, and an Incident Response Retainer keeps a known path to respond if you find a system was exposed before patching.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| Windows 10 Version 1607 | 10.0.14393.0 – < 10.0.14393.9512 | 10.0.14393.9512 |
| Windows 10 Version 1809 | 10.0.17763.0 – < 10.0.17763.9245 | 10.0.17763.9245 |
| Windows 10 Version 21H2 | 10.0.19044.0 – < 10.0.19044.7725 | 10.0.19044.7725 |
| Windows 10 Version 22H2 | 10.0.19045.0 – < 10.0.19045.7725 | 10.0.19045.7725 |
| Windows Server 2012 | 6.2.9200.0 – < 6.2.9200.26349 | 6.2.9200.26349 (Server Core installation) 6.2.9200.26349 R2 6.3.9600.23398 R2 (Server Core installation) 6.3.9600.23398 |
| Windows Server 2012 (Server Core installation) | 6.2.9200.0 – < 6.2.9200.26349 | 6.2.9200.26349 |
| Windows Server 2012 R2 | 6.3.9600.0 – < 6.3.9600.23398 | 6.3.9600.23398 (Server Core installation) 6.3.9600.23398 |
| Windows Server 2012 R2 (Server Core installation) | 6.3.9600.0 – < 6.3.9600.23398 | 6.3.9600.23398 |
| Windows Server 2016 | 10.0.14393.0 – < 10.0.14393.9512 | 10.0.14393.9512 (Server Core installation) 10.0.14393.9512 |
| Windows Server 2016 (Server Core installation) | 10.0.14393.0 – < 10.0.14393.9512 | 10.0.14393.9512 |
| Windows Server 2019 | 10.0.17763.0 – < 10.0.17763.9245 | 10.0.17763.9245 (Server Core installation) 10.0.17763.9245 |
| Windows Server 2019 (Server Core installation) | 10.0.17763.0 – < 10.0.17763.9245 | 10.0.17763.9245 |