Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
7.8
CVE-2026-85880: Windows 10/Server 2012 could let local users gain admin rights
CVE-2026-85880 · published 11 days ago · actively exploited
Summary
Certain versions of Windows 10 (1607, 1809, 21H2, 22H2) and Windows Server 2012 contain a flaw in the Advanced Local Procedure Call component that may let a user with limited access raise their privileges to an administrator level. Install the latest Microsoft security updates promptly to protect your systems.
What to do
- Update microsoft windows 10 version 1607 to version 10.0.14393.9512 or later.
- Update microsoft windows 10 version 1809 to version 10.0.17763.9245 or later.
- Update microsoft windows 10 version 21h2 to version 10.0.19044.7725 or later.
- Update microsoft windows 10 version 22h2 to version 10.0.19045.7725 or later.
- Update microsoft windows server 2012 to version 6.2.9200.26349 or later.
- Update microsoft windows server 2012 (server core installation) to version 6.2.9200.26349 or later.
- Update microsoft windows server 2012 r2 to version 6.3.9600.23397 or later.
- Update microsoft windows server 2012 r2 (server core installation) to version 6.3.9600.23397 or later.
- Update microsoft windows server 2016 to version 10.0.14393.9512 or later.
- Update microsoft windows server 2016 (server core installation) to version 10.0.14393.9512 or later.
- Update microsoft windows server 2019 to version 10.0.17763.9245 or later.
- Update microsoft windows server 2019 (server core installation) to version 10.0.17763.9245 or later.
- Update microsoft windows server 2022 to version 10.0.20348.5622 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | windows 10 version 1607 | < 10.0.14393.9512 |
| microsoft | windows 10 version 1809 | < 10.0.17763.9245 |
| microsoft | windows 10 version 21h2 | < 10.0.19044.7725 |
| microsoft | windows 10 version 22h2 | < 10.0.19045.7725 |
| microsoft | windows server 2012 | < 6.2.9200.26349 |
| microsoft | windows server 2012 (server core installation) | < 6.2.9200.26349 |
| microsoft | windows server 2012 r2 | < 6.3.9600.23397 |
| microsoft | windows server 2012 r2 (server core installation) | < 6.3.9600.23397 |
| microsoft | windows server 2016 | < 10.0.14393.9512 |
| microsoft | windows server 2016 (server core installation) | < 10.0.14393.9512 |
| microsoft | windows server 2019 | < 10.0.17763.9245 |
| microsoft | windows server 2019 (server core installation) | < 10.0.17763.9245 |
| microsoft | windows server 2022 | < 10.0.20348.5622 |
| microsoft | windows | All versions |
Original advisory text
Microsoft Windows Heap-Based Buffer Overflow Vulnerability
Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allows an attacker to elevate privileges locally.
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85880 vendor-advisory patch
Severity
7.8
High
CVSS 3.1: 7.8 (MITRE)
Exploitation
Known exploited
Listed in the CISA KEV catalogue - exploitation confirmed in the wild.
EPSS <1%
Type
CWE-122Heap-based Buffer Overflow
CWE-908Use of Uninitialized Resource
Timeline
Published8 Sep 2026
Updated19 Sep 2026
First seen8 Sep 2026
Track software like this
Free during beta