ZeroHour

CVE-2026-69874

mass

Untrusted pointer dereference in Windows ALPC allows local privilege escalation

CVSS 3.1
8.2 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-69874 is an untrusted pointer dereference (CWE-822) in the Windows Advanced Local Procedure Call (ALPC) facility, the inter-process communication mechanism used between applications and system components. An attacker authorized on the host (CVSS indicates high privileges are required) can trigger the flaw by causing Windows to dereference an attacker-influenced pointer during ALPC handling, corrupting memory in a more privileged context. Successful exploitation grants elevation of privilege, reflected in the CVSS scope change and high confidentiality, integrity, and availability impacts, meaning the attacker gains rights beyond their starting level, likely system-level privileges. All Windows deployments that include the affected ALPC implementation are potentially affected, with the greatest risk on hosts where users can sign in and run code locally, especially with administrative sessions. There is no evidence of exploitation so far: the flaw is not in CISA's KEV catalog, no public proof-of-concept is known, and EPSS estimates only a ~0.3% chance of exploitation in the next 30 days.

What to do: Apply the Microsoft security update that addresses CVE-2026-69874 via Windows Update, and check the MSRC advisory for the exact list of affected Windows versions and the corresponding KB. Until patched, restrict interactive and administrative logon on shared, multi-user, and server systems to trusted accounts, since exploitation requires local access with high privileges. Because there is no public PoC or known in-the-wild exploitation, this can follow normal patch-cadence timelines, but verify the fix is deployed across all Windows endpoints and servers.

Affected
Microsoft Windows (ALPC / Advanced Local Procedure Call component)
Estimated exposure
mass≈1 billion+ Windows devices (ALPC is a core Windows component present on essentially all Windows client and server installations) — Windows runs on more than a billion active devices per Microsoft and ALPC is shipped as a core operating-system component in every Windows installation, though actual exploitability additionally requires local access by an authorized,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Untrusted pointer dereference in Windows ALPC allows an authorized attacker to elevate privileges locally.

Weakness
CWE-822
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.