CVE-2026-85880
9.5 CISA KEVMicrosoft · Windows
A heap-based buffer overflow in the Windows ALPC subsystem allows an authenticated attacker to achieve local privilege escalation.
Executive summary
This critical heap-based buffer overflow vulnerability in Microsoft Windows is currently being exploited in the wild, posing a severe risk of unauthorized privilege escalation.
Vulnerability
This vulnerability involves a heap-based buffer overflow within the Windows Advanced Local Procedure Call (ALPC) subsystem, which can be triggered by an authenticated local attacker to gain elevated privileges.
Business impact
The vulnerability carries a CVSS score of 9.5, reflecting its potential for total system compromise when exploited by a local user. Successful exploitation allows an attacker to bypass security boundaries, potentially leading to full administrative control, data theft, or persistence on the affected host. Given its inclusion in the CISA Known Exploited Vulnerabilities (KEV) catalog, the urgency of this remediation is extreme.
Remediation
Immediate Action: Apply the vendor-provided security updates immediately to the affected Windows builds as listed in the Microsoft Update Guide.
Proactive Monitoring: Monitor system logs for unusual ALPC activity or suspicious processes attempting to execute with elevated privileges.
Compensating Controls: Since this is a local privilege escalation, ensure that endpoint detection and response (EDR) solutions are active to identify and block post-exploitation behaviors.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Due to confirmed active exploitation and the critical nature of the ALPC subsystem, organizations must prioritize patching these systems immediately. Failure to address this vulnerability allows attackers who have already gained initial low-level access to escalate their permissions to the highest level, effectively compromising the entire system. Please verify deployment of the provided fixed versions against your current inventory to ensure full coverage.
More Microsoft CVEs all →
History
- Disclosed CVE record published
- Added to CISA KEV confirmed active exploitation
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief kev section