Skip to content

CVE-2026-85880

Windows ALPC heap-based buffer overflow allows local privilege escalation (CVE-2026-85880)

High 7.8 KEV Vendor: Microsoft Published

CVE-2026-85880 is a heap-based buffer overflow in Windows ALPC. An authenticated local attacker can exploit it to elevate privileges, and it is recorded as actively exploited by CISA KEV and Microsoft. Patched Windows builds are available.

What happened

A heap-based buffer overflow in the Windows Advanced Local Procedure Call (ALPC) component allows an attacker who already has low-privileged local access to elevate to higher privileges on the system. The attack vector is local, needs no user interaction, and the CVSS 3.1 score is 7.8 (high), with high impact on confidentiality, integrity and availability.

CISA's Known Exploited Vulnerabilities catalog and Microsoft's Security Response Center record this vulnerability as actively exploited. Microsoft rates it Important. Because ALPC is a core Windows inter-process communication mechanism, any unpatched Windows 10 or Windows Server system in the affected build ranges should be treated as exposed to a working local privilege escalation technique.

Who is affected

Affected products and version ranges are:

  • Windows 10 Version 1607, before 10.0.14393.9512
  • Windows 10 Version 1809, before 10.0.17763.9245
  • Windows 10 Version 21H2, before 10.0.19044.7725
  • Windows 10 Version 22H2, before 10.0.19045.7725
  • Windows Server 2012 and Server Core installation, before 6.2.9200.26349
  • Windows Server 2012 R2 and Server Core installation, before 6.3.9600.23398
  • Windows Server 2016 and Server Core installation, before 10.0.14393.9512
  • Windows Server 2019 and Server Core installation, before 10.0.17763.9245

These are standard Windows desktop and server builds. The relevant devices include any that allow low-privileged local logon or execution, whether staff workstations, shared or lab machines, RDS hosts, or infrastructure servers with user logon rights.

What to do now

  1. Apply Microsoft's fixed builds from the September 2026 security update. Fixed OS builds are: Windows 10 1607 10.0.14393.9512 (KB5123099); Windows 10 1809 and Windows Server 2019 10.0.17763.9245 (KB5122876); Windows 10 21H2 10.0.19044.7725 and Windows 10 22H2 10.0.19045.7725 (KB5122878); Windows Server 2012 6.2.9200.26349 (KB5123065); Windows Server 2012 R2 6.3.9600.23398 (KB5123066); Windows Server 2016 10.0.14393.9512 (KB5123099); Windows Server 2022 10.0.20348.5622 (KB5122882).
  2. Prioritise systems where unprivileged local sign-in is permitted. CISA KEV gives a remediation due date of 2026-09-22 for this CVE.
  3. Microsoft's advisory does not list a workaround. While you deploy, enforce least privilege: remove unnecessary local logon rights, separate administrative accounts, and limit the ability of standard users to run untrusted code.

Beyond the patch

Patched systems close the door, but with an actively exploited local privilege escalation the question is what may already have happened on the endpoint before the update landed. Managed Detection & Response (MDR) provides telemetry to spot post-exploitation behaviour that typically follows local elevation, and an Incident Response Retainer keeps a known path to respond if you find a system was exposed before patching.

Affected and fixed versions

ProductAffectedFixed in
Windows 10 Version 160710.0.14393.0 – < 10.0.14393.951210.0.14393.9512
Windows 10 Version 180910.0.17763.0 – < 10.0.17763.924510.0.17763.9245
Windows 10 Version 21H210.0.19044.0 – < 10.0.19044.772510.0.19044.7725
Windows 10 Version 22H210.0.19045.0 – < 10.0.19045.772510.0.19045.7725
Windows Server 20126.2.9200.0 – < 6.2.9200.263496.2.9200.26349
(Server Core installation) 6.2.9200.26349
R2 6.3.9600.23398
R2 (Server Core installation) 6.3.9600.23398
Windows Server 2012 (Server Core installation)6.2.9200.0 – < 6.2.9200.263496.2.9200.26349
Windows Server 2012 R26.3.9600.0 – < 6.3.9600.233986.3.9600.23398
(Server Core installation) 6.3.9600.23398
Windows Server 2012 R2 (Server Core installation)6.3.9600.0 – < 6.3.9600.233986.3.9600.23398
Windows Server 201610.0.14393.0 – < 10.0.14393.951210.0.14393.9512
(Server Core installation) 10.0.14393.9512
Windows Server 2016 (Server Core installation)10.0.14393.0 – < 10.0.14393.951210.0.14393.9512
Windows Server 201910.0.17763.0 – < 10.0.17763.924510.0.17763.9245
(Server Core installation) 10.0.17763.9245
Windows Server 2019 (Server Core installation)10.0.17763.0 – < 10.0.17763.924510.0.17763.9245

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.