CVE-2026-85880: Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.
Other sources
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.23397Patch KB5123066 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.26349Patch KB5123065 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.9512Patch KB5123099 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.7725Patch KB5122878 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.7725Patch KB5122878 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.9245Patch KB5122876 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.5622Patch KB5122882
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker must already be authorized on a vulnerable Windows system and able to execute locally. The issue is not described as remotely exploitable or requiring user interaction.
What is the potential impact after exploitation?
Successful exploitation allows local elevation of privilege and is rated with high impact to confidentiality, integrity, and availability. An attacker could gain privileges beyond those of their existing authorized account.
Which systems should be prioritized?
Prioritize Microsoft Windows 10 and Windows Server 2012, 2012 R2, 2016, 2019, and 2022 systems, especially where untrusted or lower-privileged users can log on or run code. The vulnerability is listed in KEV as exploited as of 2026-09-08.