Impact
This vulnerability is a type‑confusion flaw in the Windows Ancillary Function Driver for WinSock that permits an authorized local user to access resources with an incompatible type, elevating the user’s privileges to an unintended level. The flaw allows the attacker to reach a higher privilege tier than originally granted, enabling potential system‑wide changes.
Affected Systems
The flaw affects Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1, 22H3; and all Windows Server releases from 2012 through 2025, covering both standard and Server Core installations on x86, x64 and arm64 architectures.
Risk and Exploitability
With a CVSS score of 7.8 the vulnerability is classified as high severity. The EPSS score is not available and the issue is not listed in CISA KEV, indicating no publicly confirmed exploits. The description explicitly requires the attacker to be an authorized local user; thus the attack vector is local and the risk is limited to environments where such accounts exist and remain unpatched.
OpenCVE Enrichment