Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days

https://www.securityweek.com/wp-content/uploads/2023/12/Microsoft-Security-leaders.jpg

Microsoft on Tuesday rolled out a record number of patches, fixing 974 CVEs across its products, including two vulnerabilities exploited in the wild as zero-days.

The first exploited zero-day, CVE-2026-85880, is a heap buffer overflow issue in the Windows Advanced Local Procedure Call (ALPC) that could allow a local attacker to gain System privileges.

“An attacker who can execute code in a low-privilege AppContainer could exploit this vulnerability locally to escape the sandbox and elevate privileges on the affected system. No additional user interaction is required,” Microsoft notes in its advisory.

Microsoft has not patched an ALPC flaw since April 2023, and CVE-2026-85880 is the second zero-day in the component to be resolved in nearly four years, after CVE-2023-21674 in January 2023, Tenable senior staff research engineer Satnam Narang points out.

The second zero-day, CVE-2026-81963, is an improper link resolution before file access (‘link following’) defect in...

Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE

Read more