Back

Windows ALPC Elevation of Privilege Vulnerability

CVE-2026-85880
Sep 16, 2026

Microsoft acknowledges a recently identified local Elevation of Privilege (EoP) vulnerability in the Windows Advanced Local Procedure Call (ALPC) kernel subsystem. This flaw stems from improper bounds validation of input message lengths and pointer buffers during inter-process communication (heap-based buffer overflow, CWE-122). An authenticated attacker with low privileges could exploit this flaw to execute arbitrary code with elevated privileges, compromise kernel integrity, and gain full control of the affected host. Active in-the-wild exploitation has been observed. The vulnerability has been assessed as High severity (CVSS v3.1: 7.8).

The vulnerability arises from insufficient boundary checks when processing malformed message packets sent to a Windows ALPC port from user-mode code. Specifically, an authenticated attacker—even operating from within restricted AppContainer sandboxes—can execute a crafted binary to send specially crafted packets without requiring user interaction. This corrupts adjacent kernel heap memory, enables control flow hijacking, escapes sandbox isolation boundaries, and escalates execution privileges directly to NT AUTHORITY\SYSTEM. In observed attacks, adversaries have weaponized this vulnerability as a post-exploitation stage to dump LSASS credentials and deploy secondary payloads.

Coordinated cumulative security updates resolving this vulnerability were released during the September 2026 Patch Tuesday release cycle (2026-09-08). Users and system administrators are strongly encouraged to apply the latest security updates (KB5122876, KB5122878, KB5122882, KB5123065, KB5123066, or KB5123099, depending on the OS edition) via Windows Update, WSUS, or Microsoft Intune/MECM, followed by a mandatory system reboot. In addition, defensive endpoint detection signatures and threat intelligence indicators have been deployed across Microsoft Defender Antivirus and Microsoft Defender for Endpoint.

Key Details:

·         Vulnerability Type: Local Elevation of Privilege (EoP) / Heap-based Buffer Overflow (CWE-122)

·         Affected Versions: Windows 10 (Versions 1607, 1809, 21H2, 22H2) and Windows Server (Versions 2012, 2012 R2, 2016, 2019, 2022)

·         Cause: Improper bounds validation of input message lengths and pointer buffers in the ALPC kernel communication interface

·         Potential Impact: An attacker with local authenticated access can break sandbox isolation, escalate privileges to NT AUTHORITY\SYSTEM, gain full control over host data/services (including credential theft from LSASS), and establish persistence

·         CVE ID: CVE-2026-85880

Case References:

·         https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85880

·         CISA Known Exploited Vulnerabilities (KEV) Catalog (Added September 2026)

Customers are strongly advised to deploy the September 2026 Cumulative Security Updates immediately across all affected Windows workstations and servers.

 

*For any further assistance regarding this issue please contact your sales representative, or create a new support ticket at https://esupport.gigabyte.com