Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.8

CVE-2026-85880: Windows 10/Server 2012 could let local users gain admin rights

CVE-2026-85880 · published 11 days ago · actively exploited
Summary

Certain versions of Windows 10 (1607, 1809, 21H2, 22H2) and Windows Server 2012 contain a flaw in the Advanced Local Procedure Call component that may let a user with limited access raise their privileges to an administrator level. Install the latest Microsoft security updates promptly to protect your systems.

What to do
  • Update microsoft windows 10 version 1607 to version 10.0.14393.9512 or later.
  • Update microsoft windows 10 version 1809 to version 10.0.17763.9245 or later.
  • Update microsoft windows 10 version 21h2 to version 10.0.19044.7725 or later.
  • Update microsoft windows 10 version 22h2 to version 10.0.19045.7725 or later.
  • Update microsoft windows server 2012 to version 6.2.9200.26349 or later.
  • Update microsoft windows server 2012 (server core installation) to version 6.2.9200.26349 or later.
  • Update microsoft windows server 2012 r2 to version 6.3.9600.23397 or later.
  • Update microsoft windows server 2012 r2 (server core installation) to version 6.3.9600.23397 or later.
  • Update microsoft windows server 2016 to version 10.0.14393.9512 or later.
  • Update microsoft windows server 2016 (server core installation) to version 10.0.14393.9512 or later.
  • Update microsoft windows server 2019 to version 10.0.17763.9245 or later.
  • Update microsoft windows server 2019 (server core installation) to version 10.0.17763.9245 or later.
  • Update microsoft windows server 2022 to version 10.0.20348.5622 or later.
Affected software
VendorProductAffected versions
microsoft windows 10 version 1607 < 10.0.14393.9512
microsoft windows 10 version 1809 < 10.0.17763.9245
microsoft windows 10 version 21h2 < 10.0.19044.7725
microsoft windows 10 version 22h2 < 10.0.19045.7725
microsoft windows server 2012 < 6.2.9200.26349
microsoft windows server 2012 (server core installation) < 6.2.9200.26349
microsoft windows server 2012 r2 < 6.3.9600.23397
microsoft windows server 2012 r2 (server core installation) < 6.3.9600.23397
microsoft windows server 2016 < 10.0.14393.9512
microsoft windows server 2016 (server core installation) < 10.0.14393.9512
microsoft windows server 2019 < 10.0.17763.9245
microsoft windows server 2019 (server core installation) < 10.0.17763.9245
microsoft windows server 2022 < 10.0.20348.5622
microsoft windows All versions
Original advisory text
Microsoft Windows Heap-Based Buffer Overflow Vulnerability
Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allows an attacker to elevate privileges locally.
Severity
7.8 High
CVSS 3.1: 7.8 (MITRE)
Exploitation
Known exploited
Listed in the CISA KEV catalogue - exploitation confirmed in the wild.
EPSS <1%
Type
CWE-122Heap-based Buffer Overflow
CWE-908Use of Uninitialized Resource
Timeline
Published8 Sep 2026
Updated19 Sep 2026
First seen8 Sep 2026
Sources
CVE-2026-85880 · MITRE
CVE-2026-85880 · CISA KEV
Track software like this
Free during beta