Knox CVE Database
/
CVE-2026-85880
High
7.8

CVE-2026-85880: Microsoft Windows Heap-Based Buffer Overflow Vulnerability

Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allows an attacker to elevate privileges locally.

Added to the CISA KEV catalog:
September 8, 2026

Overview

A heap-based buffer overflow in the Windows Advanced Local Procedure Call (ALPC) subsystem allows a locally authenticated user to escalate privileges on affected systems. By sending crafted ALPC messages, an attacker with only basic user access can corrupt privileged memory and gain elevated control over the host. Affected versions span Windows 10 (versions 1607 through 22H2) and Windows Server releases from 2012 through 2022, all prior to their respective patched builds.

Vulnerability details

Affected vendor
Microsoft
Affected product
Windows
Weakness type (CWE)
CWE-122, CWE-908

The Windows ALPC subsystem is an inter-process communication mechanism used extensively by the operating system for local message passing between user-mode and kernel or privileged components. A heap-based buffer overflow (CWE-122) occurs when crafted input causes the ALPC handler to write beyond the bounds of a heap allocation, corrupting adjacent memory. A secondary weakness, use of uninitialized heap memory (CWE-908), compounds the corruption by allowing uninitialized buffer contents to influence control flow or data. Together, these conditions create a memory-corruption path that the operating system's privilege boundary cannot contain.


An attacker who holds a standard local user account sends specially crafted ALPC messages to the vulnerable subsystem. No additional privileges, no user interaction from another party, and no complex preconditions are required beyond that authenticated local session. Successful exploitation corrupts kernel or privileged process memory in a way that allows the attacker to gain elevated privileges, likely equivalent to SYSTEM, with full confidentiality, integrity, and availability impact on the host. The attack is entirely local and does not require network access.

Severity and impact

7.8
High
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack vector
Local
Attack complexity
Low
Privileges required
Low
User interaction
None
Scope
Unchanged
Confidentiality impact
High
Integrity impact
High
Availability impact
High

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Monitor Windows Security event logs for unexpected privilege changes (Event ID 4672 or 4673) originating from low-privilege user accounts, particularly where no corresponding administrative action or scheduled task explains the elevation.
  • Audit process creation events (Event ID 4688 or Sysmon Event ID 1) for high-integrity or SYSTEM-level child processes spawned from user-context parents, which may indicate a successful local privilege escalation via ALPC.
  • Review endpoint detection telemetry for anomalous ALPC port connections or handle operations from standard user processes to privileged system components, especially where the source process has no legitimate reason to communicate with those targets.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see References) guidance and CISA’s “Forensics Triage Requirements” (see References). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
September 22, 2026

Additional hardening

  • Apply the vendor-supplied security updates: Windows 10 1607 and Server 2016 to build 10.0.14393.9512 or later; Windows 10 1809 and Server 2019 to 10.0.17763.9245 or later; Windows Server 2022 to 10.0.20348.5622 or later. See References for the full boundary list covering additional versions.
  • Restrict interactive and remote local logon rights to only accounts that require them, reducing the pool of principals who can reach the ALPC interface with the low-privilege access this flaw requires.
  • Deploy a host-based endpoint detection and response (EDR) agent with memory-protection capabilities (heap spray detection, exploit guard) to raise the cost of reliable heap corruption on unpatched systems.
  • Prioritize patching on systems where standard user accounts are broadly provisioned, such as shared workstations, VDI environments, and terminal servers, where the local-access precondition is easiest to satisfy.

Key dates

Published (NVD)
September 8, 2026
Added to CISA KEV
September 8, 2026
Remediation deadline
September 22, 2026
Last updated
September 9, 2026

References

Frequently asked questions

Does CVE-2026-85880 affect my FedRAMP authorization?

If Microsoft Windows runs inside your authorization boundary, CVE-2026-85880 is a direct concern for your FedRAMP authorization. CISA has listed this vulnerability in its Known Exploited Vulnerabilities (KEV) catalog, with a remediation deadline of September 22, 2026. An unpatched KEV inside your boundary is an assessor finding. You must either remediate it or formally document a mitigation before your assessor and sponsoring agency raise it during review.

How does Knox help me handle CVE-2026-85880?

Knox does not patch Microsoft Windows on your behalf. Under the FedRAMP shared-responsibility model, remediating CVE-2026-85880 is your obligation. What Knox provides is the pre-authorized, single-tenant boundary in which you carry out that remediation, along with Knox's automated continuous monitoring platform and audit-artifact coverage to document the fix for your next assessment. The work of applying the patch is yours; maintaining a compliant posture while you do it is not something you manage alone.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues on a continuous basis. When something like CVE-2026-85880 surfaces, exposure is identified through ongoing monitoring rather than surfacing for the first time during an assessor review, giving you time to act before it becomes a formal finding.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

What happens if CVE-2026-85880 isn't remediated by September 22, 2026?

An unremediated CVE-2026-85880 becomes a Plan of Action and Milestones (POA&M) item. A growing POA&M list is precisely what turns a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Closing out the finding and documenting the remediation is what keeps your authorization intact and the agency relationship on solid footing.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.