Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
Prioritize patching. It under exploitation confirmed by CISA.
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
A flaw in Windows ALPC allows someone with local access to exploit a buffer overflow and gain higher system privileges. This is dangerous because it lets an attacker take control of critical system functions.
Heap-based buffer overflow in Windows Advanced Local Procedure Call (ALPC) subsystem enables privilege escalation via malformed message handling. Requires local authentication; successful exploitation grants elevated privileges on the target system.