CVE-2026-85880 Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
CVSS vector modified to correct the temporal Exploit Code Maturity setting. This is an informational change only.
Microsoft 2 versions
-
2 new sentences, beginning: “CVSS vector modified to correct the temporal Exploit Code Maturity setting.”
CVE-2026-85880 Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
CVSS vector modified to correct the temporal Exploit Code Maturity setting. This is an informational change only.
-
CVE-2026-85880 Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.
Versions are compared on the headline and summary the publisher puts in their feed. An edit to the body of an article that leaves both untouched will not appear here.
Why am I seeing this Ranked on source trust — Microsoft
It ranks mainly on source trust: Microsoft is the most reliable outlet we track on this subject, and is the only one on the story so far.
It clears the bar without leading strongly on any one factor. A middling score is not a claim that the story is important — only that nothing about it is weak.
Link-outLink-out, because it scores 0.41, below the 0.50 bar for a write-up. Link-out means we point at the publisher and say nothing of our own.
| Factor | Weight | Score | Contribution | Where it came from |
|---|---|---|---|---|
| Corroboration | 0.35 | 0.39 | +0.135 33% | 1 independent org on the story. Tier-3 aggregators never corroborate — they can show something is circulating, never that it is true. |
| Source trustleads | 0.25 | 1.00 | +0.250 62% | Microsoft is the highest-trust source on this story and is first-party — the organisation announcing its own news. Trust is taken from the best source, not averaged. |
| Pickup rate | 0.20 | 0.00 | +0.000 0% | One counted organisation, so there is no spread to measure — nothing has picked this up to set a rate. |
| Freshness | 0.20 | 0.10 | +0.021 5% | Halves every 10 hours from the newest item on the story. This is the only factor that rewards a story for nothing more than being recent. |
Corroboration counts distinct organisations, once each, and only from tiers 1 and 2. Freshness halves every 10 hours, so this ranking is a snapshot and will differ at the next build.
What happened
CVSS vector modified to correct the temporal Exploit Code Maturity setting. Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.
Listed in CISA's Known Exploited Vulnerabilities catalog — attackers are already using it.
- Impact
- Privilege Escalation
- Product
- Windows Advanced Local Procedure Call (ALPC)
- CISA deadline
- 3 business days
How this story arrived
Ordered by when each source was first observed, which is what the velocity figure is computed from. Publishers backdate; observed order does not.
- 01 Microsoftfirst-party first seen CVE-2026-85880 Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerabi
Overclock clusters coverage from independent sources and grades it automatically. The figures above are computed, not editorial. This page summarises and links to reporting by the outlets named — follow the links for the original work.