CVE-2026-85880 – Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability

CVSS 7.8 IMPORTANT Zero Day – Immediate Deployment

“This ALPC flaw is already being exploited, and a successful attack can turn low-privilege code execution into full SYSTEM control.”

A heap-based buffer overflow vulnerability in Windows Advanced Local Procedure Call (ALPC) allows an authorized local attacker to elevate privileges. An attacker who can execute code from a low-privilege AppContainer can exploit the vulnerability to escape the sandbox and obtain SYSTEM privileges without requiring user interaction.

Key Details

Affected Product
Microsoft Windows 10 1607
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
CWE Classification
CWE-122
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.