Database/Kernel, userspace & hypervisor

Windows Update Stack: link following lets a local user escalate to SYSTEM
Impact
The update servicing stack resolves a path without checking that it is not a symlink or junction the caller controls, so an authorized local user can redirect a privileged file operation and elevate. On a Windows Server 2025 node - including Server Core - that turns any local account or service identity into full control of the host. This matters on the Windows side of a GPU estate: management jump hosts, license servers, and Windows Server 2025 hosts running GPU workloads or Hyper-V. CISA lists it as exploited in the wild, which moves it from a routine Patch Tuesday elevation to something worth a near-term window. Windows 11 23H2 through 26H1 are also listed, but those are client SKUs outside this database's scope.
Who can reach it
A local, already-authenticated user or a compromised low-privilege service on an affected Windows host. No user interaction. Not reachable over the network on its own - it is the second stage after any initial foothold.
What to do
Install the September 2026 cumulative update for the affected SKU; the MSRC entry carries the per-SKU KB numbers. Windows servicing-stack patches require a reboot, so plan a per-node window and drain or fail over the host first. Microsoft publishes no mitigation short of the update, and because the flaw is exploited in the wild there is no useful "wait for the next window" position on internet-adjacent or multi-admin hosts.
References
Related entries
- Windows ALPC: heap overflow gives a local user privilege escalation to SYSTEMCVE-2026-85880 · Windows ALPC (Advanced Local Procedure Call)High
- Linux kernel virtio-gpu: unvalidated EDID block offset lets a malicious backend read past a kernel bufferCVE-2026-68255 · Linux kernel drm/virtio (virtio_get_edid_block response bounds)High
- Linux kernel (drivers/pci): The option-ROM parser trusts the header and data-structure offsets it reads out of theCVE-2026-72487 · Linux kernel (drivers/pci)High
- Xen qemu-xen-traditional device model hw/pt-msi.c (MSI-X passthrough): Buffer overflow on the MSI-X table write pathCVE-2015-8554 · Xen qemu-xen-traditional device model hw/pt-msi.c (MSI-X passthrough)High
- Linux kernel RDS net/rds/recv.c - rds_inc_info_copy: A structure member is left uninitialised before the RDS messageCVE-2016-5244 · Linux kernel RDS net/rds/recv.c - rds_inc_info_copyHigh
- QEMU (virtio-net): Heap use-after-free in virtio_net_receive_rcu - guest-to-host code execution in the QEMU processCVE-2021-3748 · QEMU (virtio-net)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.