CVE-2026-85880

HIGH Status: Analyzed

CVSS Scores

CVSS v3.x Base Score
7.8
HIGH

Description

Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.

Published
September 8, 2026 6:21 PM
Last Modified
September 8, 2026 7:28 PM
Source
[email protected]

Weaknesses (CWE)

CWE-122 CWE-908

References

Affected Configurations

[
    {
        "nodes": [
            {
                "operator": "OR",
                "negate": false,
                "cpeMatch": [
                    {
                        "vulnerable": true,
                        "criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:*",
                        "versionEndExcluding": "10.0.14393.9512",
                        "matchCriteriaId": "F5BC051B-C14F-43DF-B3A2-A32EE0DDC142"
                    },
                    {
                        "vulnerable": true,
                        "criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*",
                        "versionEndExcluding": "10.0.14393.9512",
                        "matchCriteriaId": "D8DA8FA6-35F6-4E0F-A9C0-37CB88186C5B"
                    },
                    {
                        "vulnerable": true,
                        "criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*",
                        "versionEndExcluding": "10.0.17763.9245",
                        "matchCriteriaId": "81786843-7838-4C74-AEA6-E64B6B354387"
                    },
                    {
                        "vulnerable": true,
                        "criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*",
                        "versionEndExcluding": "10.0.17763.9245",
                        "matchCriteriaId": "D5E29D31-09E1-4C19-AAB0-191AA960C778"
                    },
                    {
                        "vulnerable": true,
                        "criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:arm64:*",
                        "versionEndExcluding": "10.0.19044.7725",
                        "matchCriteriaId": "26BFC889-B503-48BF-9D82-5B3043D9A6B3"
                    },
                    {
                        "vulnerable": true,
                        "criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x64:*",
                        "versionEndExcluding": "10.0.19044.7725",
                        "matchCriteriaId": "E6F2C029-D78A-4FAA-B2E8-FD79C2CABC32"
                    },
                    {
                        "vulnerable": true,
                        "criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x86:*",
                        "versionEndExcluding": "10.0.19044.7725",
                        "matchCriteriaId": "0B423BD2-DDDC-4869-9B98-3275F53B92F1"
                    },
                    {
                        "vulnerable": true,
                        "criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:arm64:*",
                        "versionEndExcluding": "10.0.19045.7725",
                        "matchCriteriaId": "254EF7C4-707D-4480-BC27-56F64175A9AD"
                    },
                    {
                        "vulnerable": true,
                        "criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x64:*",
                        "versionEndExcluding": "10.0.19045.7725",
                        "matchCriteriaId": "B318C958-84F6-4E33-A95C-6E95C7E286EB"
                    },
                    {
                        "vulnerable": true,
                        "criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x86:*",
                        "versionEndExcluding": "10.0.19045.7725",
                        "matchCriteriaId": "9828DC67-F252-4E2B-AFE9-C404BAF414E0"
                    },
                    {
                        "vulnerable": true,
                        "criteria": "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*",
                        "matchCriteriaId": "A7DF96F8-BA6A-4780-9CA3-F719B3F81074"
                    },
                    {
                        "vulnerable": true,
                        "criteria": "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*",
                        "matchCriteriaId": "DB18C4CE-5917-401E-ACF7-2747084FD36E"
                    },
                    {
                        "vulnerable": true,
                        "criteria": "cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*",
                        "versionEndExcluding": "10.0.14393.9512",
                        "matchCriteriaId": "C7CF508B-369A-4854-97BF-EE90E0A5BF7B"
                    },
                    {
                        "vulnerable": true,
                        "criteria": "cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*",
                        "versionEndExcluding": "10.0.17763.9245",
                        "matchCriteriaId": "14138B1B-9554-4B1D-84C6-485FB9763DA4"
                    },
                    {
                        "vulnerable": true,
                        "criteria": "cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*",
                        "versionEndExcluding": "10.0.20348.5622",
                        "matchCriteriaId": "496A12F9-40BF-4A40-948B-BDB1C5D17DCB"
                    }
                ]
            }
        ]
    }
]

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.