Attackers are exploiting a Windows ALPC heap overflow to escape low-privilege sandboxes and reach SYSTEM.
Existing AppContainer execution is enough to reach the vulnerable path.
Supported Microsoft Windows client and server systems using the built-in ALPC inter-process communication mechanism.
Local sandbox escape and SYSTEM privilege escalation
The broken boundary is containment itself: code that was already restricted can cross the user or AppContainer boundary and become SYSTEM, and exploitation is active.
Detail and 5 sources
An attacker begins with low-privilege or AppContainer code execution, triggers the heap overflow with crafted ALPC activity and crosses into SYSTEM.
A fix is published and reaches end-of-life hardware. We do not know whether pre-fix images remain accepted or whether revocation is complete.
- access:local:unprivileged
- code running as an unprivileged local user
- interaction:none
- no user action required
- Reaches end-of-life hardware
- Yes
No public patch diff or reverse-engineering analysis was available in the reviewed material.