Vulnerability record · CVE-2026-85880 · published 8 September 2026
CVE-2026-85880: Windows ALPC heap buffer overflow allows local privilege escalation
Microsoft · Windows 10 1607
A heap-based buffer overflow in the Windows ALPC subsystem, combined with use of an uninitialized resource, lets an attacker with existing local access on a machine elevate their privileges. The flaw affects a broad set of Windows 10 and Windows Server releases, so unpatched endpoints and servers retain a local escalation path. It matters because local privilege escalation is a standard step in post-compromise chains, turning limited access into full control of the host.
Description
Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw is a local privilege escalation with high confidentiality, integrity and availability impact and is listed in CISA KEV as exploited, though it requires existing local access and has low EPSS.
What it is
A heap-based buffer overflow in the Windows ALPC subsystem, combined with use of an uninitialized resource, lets an attacker with existing local access on a machine elevate their privileges. The flaw affects a broad set of Windows 10 and Windows Server releases, so unpatched endpoints and servers retain a local escalation path. It matters because local privilege escalation is a standard step in post-compromise chains, turning limited access into full control of the host.
Impact
An attacker who already holds a low-privileged account or code execution on the host can gain high-level read, write and execution capability, effectively taking over the system. That access can be used to disable defenses, move laterally, or deploy further payloads.
Attack surface
The vulnerability is reached locally through the ALPC interface, per the CVSS vector AV:L. It requires low privileges (PR:L) and no user interaction (UI:N), so any process or user already running on the box can attempt it.
Exploitation
CISA added this to the Known Exploited Vulnerabilities catalog on 2026-09-08 with a remediation due date of 2026-09-22, indicating exploitation in the wild. EPSS is low (0.00572, roughly the 46th percentile), and no ransomware campaign use is documented.
What to do
- Apply the Microsoft security update referenced in the MSRC advisory for all listed Windows 10 and Windows Server versions; treat this as the first action given the KEV listing.
- Prioritize patching of internet-facing and high-value servers, and meet the CISA due date of 2026-09-22 for federal and aligned environments.
- Reduce the number of accounts and processes with local interactive or service access on sensitive hosts to limit who can reach the ALPC attack surface.
- Where patching cannot be completed immediately, isolate affected hosts and restrict local logon and service account rights as a temporary control.
Detection
- Monitor for unexpected privilege changes or new high-integrity processes spawned from low-privileged parents on affected Windows builds.
- Hunt for anomalous ALPC connection activity and unusual process-to-process messaging involving privileged services.
- Alert on exploitation indicators near known ALPC abuse patterns, such as crashes in ALPC-related components followed by elevated process creation.
- Track patch state of the listed Windows 10 and Windows Server versions and flag hosts still unpatched after the KEV due date.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2026-85880 to the Known Exploited Vulnerabilities catalog on 8 September 2026 as "Microsoft Windows Heap-Based Buffer Overflow Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 22 September 2026.
Affected products
8 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85880 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-85880 | US Government Resource |
Track CVE-2026-85880 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-85880), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.