Impact
The vulnerability is a type confusion flaw in the Windows Ancillary Function Driver for WinSock, exposing an attacker with local authorization to access resources using an incompatible type. Classified as CWE‑843, the flaw allows the attacker to gain higher privileges on the affected system. The impact is confined to the local user context; the elevated privilege level can enable installation of malware, modification of system files, or persistence mechanisms.
Affected Systems
Microsoft Windows 10 from version 1607 through 22H2, Windows 11 from 22H3 and from 23H2 through 25H2, and several Windows Server editions from 2008 R2 and 2012 through 2025. The affected stack includes both x86 and x64 architectures, as well as ARM64 on newer Windows 11 releases.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.8, indicating high severity, but the EPSS score is now 8%, showing a higher probability of exploitation in the wild. It is not listed in CISA’s KEV catalog, so there is no evidence of widespread exploitation yet. The attack requires local user presence; therefore, environments that reduce local user privileges or enforce least privilege mitigations can lower the risk. The lack of a publicly documented exploit does not eliminate the risk, as malicious actors can craft exploits for type‑confusion bugs.
OpenCVE Enrichment