CVE-2026-85880

Analyzed
Published: 08 Sept 2026, 17:14
Last modified:09 Sept 2026, 04:27

Vulnerability Summary

Overall Risk (default)
medium
31/100
CVSS Score
7.8 HIGH
v3.1 (cve.org)
EPSS Score
No data
KEV
Listed
CISA
1 listing
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

08 Sept 2026, 17:14
Published
Vulnerability first disclosed
08 Sept 2026, 00:00
Added to CISA KEV
Microsoft Windows Heap-Based Buffer Overflow Vulnerability
09 Sept 2026, 04:27
Last Modified
Vulnerability information updated
22 Sept 2026, 00:00
CISA Remediation Due
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Description

Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.

CVSS Metrics

  • v3.1HIGHScore: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
  • v3.1HIGHScore: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Techniques & Countermeasures

  • CWE-122Heap-based Buffer Overflow

    A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

  • CWE-908Use of Uninitialized Resource

    The product uses or accesses a resource that has not been initialized.

Affected Systems

  • microsoftwindows_10_1607

    < 10.0.14393.9512

  • microsoftwindows_10_1809

    < 10.0.17763.9245

  • microsoftwindows_10_21h2

    < 10.0.19044.7725

  • microsoftwindows_10_22h2

    < 10.0.19045.7725

  • microsoftwindows 10 version 1607

    ≥ 10.0.14393.0, < 10.0.14393.9512

  • microsoftwindows 10 version 1809

    ≥ 10.0.17763.0, < 10.0.17763.9245

  • microsoftwindows 10 version 21h2

    ≥ 10.0.19044.0, < 10.0.19044.7725

  • microsoftwindows 10 version 22h2

    ≥ 10.0.19045.0, < 10.0.19045.7725

  • microsoftwindows server 2012

    na | r2 | ≥ 6.2.9200.0, < 6.2.9200.26349

  • microsoftwindows server 2012 r2

    ≥ 6.3.9600.0, < 6.3.9600.23397

  • microsoftwindows server 2012 r2 (server core installation)

    ≥ 6.3.9600.0, < 6.3.9600.23397

  • microsoftwindows server 2012 (server core installation)

    ≥ 6.2.9200.0, < 6.2.9200.26349

  • microsoftwindows server 2016

    < 10.0.14393.9512 | ≥ 10.0.14393.0, < 10.0.14393.9512

  • microsoftwindows server 2016 (server core installation)

    ≥ 10.0.14393.0, < 10.0.14393.9512

  • microsoftwindows server 2019

    < 10.0.17763.9245 | ≥ 10.0.17763.0, < 10.0.17763.9245

  • microsoftwindows server 2019 (server core installation)

    ≥ 10.0.17763.0, < 10.0.17763.9245

  • microsoftwindows server 2022

    < 10.0.20348.5622 | ≥ 10.0.20348.0, < 10.0.20348.5622

References (2)