Skip to finding
§
High
Privilege — Windows
Confirmed
CVE-2026-85880

Attackers are exploiting a Windows ALPC heap overflow to escape low-privilege sandboxes and reach SYSTEM.

Existing AppContainer execution is enough to reach the vulnerable path.

Affects

Supported Microsoft Windows client and server systems using the built-in ALPC inter-process communication mechanism.

What it enables

Local sandbox escape and SYSTEM privilege escalation

Attacker obtains low-privilege or AppContainer code execution→↓Crafted ALPC activity triggers a heap-based buffer overflow→↓Execution crosses the AppContainer or user boundary→↓Attacker reaches SYSTEM privileges
Why this matters

The broken boundary is containment itself: code that was already restricted can cross the user or AppContainer boundary and become SYSTEM, and exploitation is active.

Detail and 5 sources
Required access

Existing low-privilege code execution, including execution inside an AppContainer sandbox

Affected versions

Supported Windows client and server releases identified in Microsoft's September 2026 advisory, Windows 10 version 1607 before build 14393.9512, Windows 10 version 1809 before build 17763.9245, Windows 10 version 21H2 before build 19044.7725, Windows 10 version 22H2 before build 19045.7725, Windows Server 2012 before build 9200.26349, Windows Server 2012 R2 before build 9600.23397, Windows Server 2016 before build 14393.9512, Windows Server 2019 before build 17763.9245, Windows Server 2022 before build 20348.5622

An attacker begins with low-privilege or AppContainer code execution, triggers the heap overflow with crafted ALPC activity and crosses into SYSTEM.

A fix is published and reaches end-of-life hardware. We do not know whether pre-fix images remain accepted or whether revocation is complete.

Evidence
Microsoft marked exploitation detectedCrowdStrike documented the AppContainer-to-SYSTEM path and heap-overflow primitivePublic proof of concept or incident artifacts
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Wednesday, September 9, 2026