Junglewise Threat Intelligence

CVE-2026-85880: Microsoft Windows heap-based buffer overflow in Advanced Local Procedure Call

CVE-2026-85880 · Severity: critical · Exploited in the wild · Published 2026-09-08

Executive brief

Windows Advanced Local Procedure Call (a core component of Windows used for inter-process communication) contains a heap memory overflow flaw that allows a local attacker to gain system-level privileges. This vulnerability is actively being exploited by attackers in the wild, making immediate patching essential to prevent unauthorized access and control of affected machines.

Technical details

A heap-based buffer overflow exists in Microsoft Windows Advanced Local Procedure Call (ALPC), a kernel-mode inter-process communication mechanism. The vulnerability allows a local attacker to overflow a heap buffer, potentially enabling arbitrary code execution with elevated privileges. The attack requires local access to the system but does not require user interaction or special privileges as a precondition. An attacker can exploit this flaw to achieve kernel-level code execution, leading to complete system compromise. The vulnerability is known to be actively exploited in the wild as of the publication date.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed
  • exploited: Known to be exploited in the wild

Related threats