GPU VulnDB

Database/Kernel, userspace & hypervisor

Windows ALPC: heap overflow gives a local user privilege escalation to SYSTEM

CVSS 7.8CVE-2026-85880Kernel, userspace & hypervisorKnown exploitedcurated

Impact

A heap-based buffer overflow in ALPC, the local IPC mechanism every Windows service uses to talk to privileged components, lets an authorized local user elevate. ALPC is not an optional role - it is present and reachable from any process on the box, so there is no configuration that removes the exposure. The affected list is the long-tail estate: Windows 10 1607/1809/21H2/22H2 and Windows Server 2012 and 2012 R2, which in a datacenter usually means old management servers, license servers, and appliance-like Windows hosts nobody wants to touch. CISA lists it as exploited in the wild. Server 2012 and 2012 R2 are out of mainstream support and only get this fix through extended security updates, so many operators will not have the patch available at all.

Who can reach it

Any local authenticated user or compromised service account on an affected Windows host. No user interaction, no special privilege beyond a foothold. Not remotely reachable by itself.

What to do

Install the September 2026 update for the affected SKU; MSRC carries the per-SKU KB numbers. For Windows Server 2012 and 2012 R2 this requires an active Extended Security Updates subscription - without one there is no fix and the host must be isolated or retired. Patching requires a reboot, so plan a per-node window. Because ALPC is always present, there is no mitigating configuration change; reducing who can log on interactively or run code on these hosts is the only stopgap.

References

Related entries

All Kernel, userspace & hypervisor entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.