Executive brief
Windows Advanced Local Procedure Call (ALPC) is a core inter-process communication mechanism used throughout Windows. A use-after-free vulnerability in ALPC allows an authorized local user to escalate privileges and gain higher-level access on the affected system, potentially compromising data confidentiality and system integrity.
Technical details
This is a use-after-free vulnerability in the Windows ALPC subsystem, a kernel-level inter-process communication mechanism. The vulnerability requires an attacker to already have local system access (authorized user context). By exploiting the use-after-free condition, an authenticated local attacker can elevate their privileges to a higher security context. The attack is local only and does not require network access. A patch is expected from Microsoft through their regular security update cycle.
Affected products
- Microsoft Windows
Timeline
- 2026-09-08: disclosed