CVE-2026-69874 – Windows ALPC Elevation of Privilege Vulnerability

CVSS 8.2 IMPORTANT Critical - Same Day Deployment

“A successful local attack could turn existing access into highly privileged control, putting sensitive Windows systems and data at risk.”

CVE-2026-69874 is a Critical elevation-of-privilege vulnerability in Windows ALPC caused by an untrusted pointer dereference. An authorized local attacker who successfully exploits the flaw could elevate privileges to Virtual Trust Level 1 (VTL1). Exploitation requires high privileges and no user interaction. The vulnerability is not publicly disclosed or known to be exploited, and exploitation is assessed as unlikely.

Key Details

Attack Vector
Local
Attack Complexity
Low
Privileges Required
High
User Interaction
None
CWE Classification
CWE-822
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.