First published · Last updated
CVE-2026-85880: Microsoft Windows Heap-Based Buffer Overflow Vulnerability
Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow that allows an attacker to elevate privileges locally. The source requires applying vendor mitigations and following CISA BOD 26-04 guidance and forensics triage requirements.
Categories: technology
Generated scores
Scores are based on the cited reporting and use a 1–10 scale. Read the methodology.
- Confidence
- 6/10
- Geographic reach
- 4/10
- Global importance
- 4/10
- Impact magnitude
- 4/10
- Positivity
- 2/10
- Urgency
- 6/10
Why it matters
Applying the vendor and CISA mitigation guidance is required to address this local privilege-elevation vulnerability.

