CVE-2026-85880

9.5 CISA KEV

Microsoft · Windows

A heap-based buffer overflow in the Windows ALPC subsystem allows an authenticated attacker to achieve local privilege escalation.

Executive summary

This critical heap-based buffer overflow vulnerability in Microsoft Windows is currently being exploited in the wild, posing a severe risk of unauthorized privilege escalation.

Vulnerability

This vulnerability involves a heap-based buffer overflow within the Windows Advanced Local Procedure Call (ALPC) subsystem, which can be triggered by an authenticated local attacker to gain elevated privileges.

Business impact

The vulnerability carries a CVSS score of 9.5, reflecting its potential for total system compromise when exploited by a local user. Successful exploitation allows an attacker to bypass security boundaries, potentially leading to full administrative control, data theft, or persistence on the affected host. Given its inclusion in the CISA Known Exploited Vulnerabilities (KEV) catalog, the urgency of this remediation is extreme.

Remediation

Immediate Action: Apply the vendor-provided security updates immediately to the affected Windows builds as listed in the Microsoft Update Guide.

Proactive Monitoring: Monitor system logs for unusual ALPC activity or suspicious processes attempting to execute with elevated privileges.

Compensating Controls: Since this is a local privilege escalation, ensure that endpoint detection and response (EDR) solutions are active to identify and block post-exploitation behaviors.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Due to confirmed active exploitation and the critical nature of the ALPC subsystem, organizations must prioritize patching these systems immediately. Failure to address this vulnerability allows attackers who have already gained initial low-level access to escalate their permissions to the highest level, effectively compromising the entire system. Please verify deployment of the provided fixed versions against your current inventory to ensure full coverage.

More Microsoft CVEs all →

History

  1. Disclosed CVE record published
  2. Added to CISA KEV confirmed active exploitation
  3. Collected by CVE Brief via github
  4. Analyst report written
  5. Published in the daily brief kev section

Sources