Severity: High
A high-severity vulnerability has been disclosed affecting Windows Advanced Local Procedure Call (ALPC), an inter-process communication mechanism used extensively across the Windows operating system.
The vulnerability, tracked as CVE-2026-85880, is a heap-based buffer overflow vulnerability in Windows ALPC (Advanced Local Procedure Call), the inter-process communication mechanism used extensively by the Windows operating system. A flaw in the way Windows ALPC handles message or port data means that an attacker can supply crafted input that causes the system to write beyond the bounds of an allocated heap buffer, corrupting adjacent memory. A locally authenticated attacker can exploit this vulnerability to elevate their privileges on the affected host, potentially achieving SYSTEM-level access without requiring administrator rights.
If an attacker has access to a low-privilege AppContainer they can use this exploit to escape the sandbox and elevate privileges. This class of vulnerability is commonly leveraged as a second-stage exploit in broader attack chains, where an attacker already holds limited local access and seeks to escalate to full control of the affected system.
As part of Beeks’ commitment to supporting operational resilience and cyber risk management, this advisory is intended to help organisations assess exposure and implement appropriate mitigations.
Affected software:
- Windows ALPC – affected Windows releases prior to the patched version
- Windows 10 1607 – 22H2
- Windows Server 2012 R2 – 2019
Immediate Recommended Actions
- Apply the latest security patches released by Microsoft to remediate this vulnerability — this is the primary and most effective remediation.
- Where immediate patching is not possible, restrict local interactive and remote access to affected systems to minimise the risk of exploitation by low-privileged users.
- Review and audit systems for indicators of unexpected privilege escalation events, particularly on hosts exposed to lower-privileged or untrusted user accounts.
Further Information:
For detailed information on the vulnerability, please refer to the following sources:
https://nvd.nist.gov/vuln/detail/CVE-2026-85880
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85880
If you have any questions or require further assistance, please contact [email protected] or reach out to your Beeks account representative.
This advisory is issued to help ensure the security of your systems and prevent unauthorised access to sensitive data. Beeks remains committed to providing timely security information and support to safeguard your infrastructure.
Beeks will continue to monitor this and related vulnerabilities and provide updates through our Security Advisory Feed.






