Database/Kernel, userspace & hypervisor

Windows ALPC: heap overflow gives a local user privilege escalation to SYSTEM
Impact
A heap-based buffer overflow in ALPC, the local IPC mechanism every Windows service uses to talk to privileged components, lets an authorized local user elevate. ALPC is not an optional role - it is present and reachable from any process on the box, so there is no configuration that removes the exposure. The affected list is the long-tail estate: Windows 10 1607/1809/21H2/22H2 and Windows Server 2012 and 2012 R2, which in a datacenter usually means old management servers, license servers, and appliance-like Windows hosts nobody wants to touch. CISA lists it as exploited in the wild. Server 2012 and 2012 R2 are out of mainstream support and only get this fix through extended security updates, so many operators will not have the patch available at all.
Who can reach it
Any local authenticated user or compromised service account on an affected Windows host. No user interaction, no special privilege beyond a foothold. Not remotely reachable by itself.
What to do
Install the September 2026 update for the affected SKU; MSRC carries the per-SKU KB numbers. For Windows Server 2012 and 2012 R2 this requires an active Extended Security Updates subscription - without one there is no fix and the host must be isolated or retired. Patching requires a reboot, so plan a per-node window. Because ALPC is always present, there is no mitigating configuration change; reducing who can log on interactively or run code on these hosts is the only stopgap.
References
Related entries
- Linux kernel virtio-gpu: unvalidated EDID block offset lets a malicious backend read past a kernel bufferCVE-2026-68255 · Linux kernel drm/virtio (virtio_get_edid_block response bounds)High
- Linux kernel (drivers/pci): The option-ROM parser trusts the header and data-structure offsets it reads out of theCVE-2026-72487 · Linux kernel (drivers/pci)High
- Xen qemu-xen-traditional device model hw/pt-msi.c (MSI-X passthrough): Buffer overflow on the MSI-X table write pathCVE-2015-8554 · Xen qemu-xen-traditional device model hw/pt-msi.c (MSI-X passthrough)High
- Linux kernel RDS net/rds/recv.c - rds_inc_info_copy: A structure member is left uninitialised before the RDS messageCVE-2016-5244 · Linux kernel RDS net/rds/recv.c - rds_inc_info_copyHigh
- QEMU (virtio-net): Heap use-after-free in virtio_net_receive_rcu - guest-to-host code execution in the QEMU processCVE-2021-3748 · QEMU (virtio-net)High
- Linux kernel (drivers/nvme/target): When the target's peer-to-peer memory pool runs dry, it still tries to return theCVE-2021-47130 · Linux kernel (drivers/nvme/target)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.