Heap-Based Buffer Overflow in Microsoft Windows ALPC Enables Local Privilege Escalation

Note: This data is for reference and cybersecurity research purposes only.CyStack advises users not to use this information for unlawful purposes.

What is CVE-2026-85880?

CVE-2026-85880 is a vulnerability classified as Heap-based Buffer Overflow and Use of Uninitialized Resource, affecting Windows 10 Version 1607 (affected versions: 10.0.14393.0 – < 10.0.14393.9512), Windows 10 Version 1809 (affected versions: 10.0.17763.0 – < 10.0.17763.9245), Windows 10 Version 21H2 (affected versions: 10.0.19044.0 – < 10.0.19044.7725), and 10 more products. This vulnerability is rated High, with a CVSS score of 7.8. This vulnerability has been observed being exploited in the wild.

Overview

Original source data

Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.

Affected products and scope

  • Microsoft Windows 10 Version 1607: affected from 10.0.14393.0 to less than 10.0.14393.9512.
  • Microsoft Windows 10 Version 1809: affected from 10.0.17763.0 to less than 10.0.17763.9245.
  • Microsoft Windows 10 Version 21H2: affected from 10.0.19044.0 to less than 10.0.19044.7725.
  • Microsoft Windows 10 Version 22H2: affected from 10.0.19045.0 to less than 10.0.19045.7725.
  • Microsoft Windows Server 2012: affected from 6.2.9200.0 to less than 6.2.9200.26349.
  • Microsoft Windows Server 2012, Server Core installation: affected from 6.2.9200.0 to less than 6.2.9200.26349.
  • Microsoft Windows Server 2012 R2: affected from 6.3.9600.0 to less than 6.3.9600.23397.
  • Microsoft Windows Server 2012 R2, Server Core installation: affected from 6.3.9600.0 to less than 6.3.9600.23397.
  • Microsoft Windows Server 2016: affected from 10.0.14393.0 to less than 10.0.14393.9512.
  • Microsoft Windows Server 2016, Server Core installation: affected from 10.0.14393.0 to less than 10.0.14393.9512.
  • Microsoft Windows Server 2019: affected from 10.0.17763.0 to less than 10.0.17763.9245.
  • Microsoft Windows Server 2019, Server Core installation: affected from 10.0.17763.0 to less than 10.0.17763.9245.
  • Microsoft Windows Server 2022: affected from 10.0.20348.0 to less than 10.0.20348.5622.

Products, branches, or configurations not listed above are not confirmed as either affected or safe.

Technical details

Microsoft Windows contains a heap-based buffer overflow in Advanced Local Procedure Call (ALPC). The flaw is classified as CWE-122, and the record also assigns CWE-908, but the available evidence does not identify the specific uninitialized resource or memory operation that causes the failure. An attacker needs local access and an accepted initial authorization level; the record requires no user interaction and describes exploitation complexity as low. The specific attacker-controlled input, ALPC message, and vulnerable handler have not been disclosed in the available evidence. The affected scope is limited to the Microsoft Windows and Windows Server branches listed in affected_summary; unlisted branches or configurations remain unconfirmed.

Exploitability

The flaw is locally reachable by an authorized attacker with low initial privileges. The record describes no required user interaction and low exploitation complexity. The record marks the vulnerability as known exploited and as having a public exploit, but it does not provide a payload, exploit chain, threat actor, victim, or specific indicator of compromise. The available evidence does not show that the flaw can be exploited directly over a network.

Technical impact

The flaw can allow an attacker with local access and low initial privileges to elevate privileges on the same system. If exploitation succeeds, the confidentiality, integrity, and availability of the affected system may all be seriously impacted according to the assessment information in the record. The scope is described as unchanged, so the available evidence does not show automatic expansion into a different security authority. The practical consequence depends on the attacker's starting rights and on the data and services hosted by the system, as well as whether the system is later used to reach other assets. The record does not confirm remote code execution, access to a particular dataset, or a specific completed incident.

Business impact

Successful exploitation could move an attacker from a low-privileged local context to a higher-privileged context on an affected system. Possible consequences include unauthorized access to data, changes that undermine system integrity, or disruption of services on that system.

  • Affected workstations, servers, and Server Core installations may become privilege escalation points after an incident has already obtained local access.
  • Operational risk is higher because the record identifies known exploitation and an available patch.
  • The available evidence does not confirm a specific intrusion, ransomware campaign, victim organization, or data loss event.

Remediation

  1. Prioritize Microsoft security updates because the record marks the vulnerability as known exploited and indicates that a patch is available.
  2. Update each affected branch to a build that is no longer within the recorded affected interval:
  • Windows 10 Version 1607 and Windows Server 2016, including Server Core: 10.0.14393.9512.
  • Windows 10 Version 1809 and Windows Server 2019, including Server Core: 10.0.17763.9245.
  • Windows 10 Version 21H2: 10.0.19044.7725.
  • Windows 10 Version 22H2: 10.0.19045.7725.
  • Windows Server 2012, including Server Core: 6.2.9200.26349.
  • Windows Server 2012 R2, including Server Core: 6.3.9600.23397.
  • Windows Server 2022: 10.0.20348.5622.
  1. Verify deployment by checking the actual installed build on each system and branch rather than relying only on a patch distribution tool's success state.
  2. If an update cannot be deployed immediately, apply the organization's local exposure reduction procedures and increase monitoring for local privilege escalation activity. The supplied evidence does not document a specific alternative mitigation, so these measures should not be treated as a fix.
  3. Assess Windows branches that are not listed separately. Do not assume that a version boundary for one branch covers another or a parallel branch.

Detection

  1. Inventory Microsoft Windows and Windows Server systems, including Server Core installations, and record their actual operating system builds.
  2. Compare each build with the affected intervals in affected_summary; do not infer the status of branches that are not listed.
  3. After deployment, recheck the installed build to confirm that the system is no longer below the applicable branch boundary.
  4. Review local privilege escalation events and unusual process behavior as additional monitoring. This is precautionary monitoring, not a confirmed indicator for this vulnerability.
  5. The available evidence does not identify an event ID, log entry, ALPC endpoint, or specific IOC. The absence of suspicious log evidence does not prove that a system is safe.
Sources (14)
Learn more

Run an in-depth assessment with complete web risk management

CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.

Explore CyStack VulnScan