Description
Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally.
Published: 2026-07-14
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from the cleartext transmission of sensitive data within the Windows Ancillary Function Driver for WinSock. An authorized attacker, who has local access, can read this data, resulting in potential leakage of confidential information. This weakness is categorized under CWE-319, which concerns information transmitted insecurely over a public channel. The primary impact is the compromise of confidentiality for data that should otherwise remain protected from local attackers. Affected systems include a wide range of Microsoft Windows operating systems: Windows 10 versions 1607, 1809, 21H2 and 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; Windows Server 2012, 2012 R2 (with and without Server Core), 2016, 2019, 2022, and 2025 versions. This extensive coverage means that any device running these OS editions may be vulnerable if the pending update is not applied. The risk assessment, based on the CVSS score of 5.5, indicates moderate severity. The EPSS score of less than 1% suggests a very low likelihood of exploitation at present, and the vulnerability is not listed in CISA's KEV catalog, further reducing its immediate threat level. However, local attackers with sufficient privileges could still disclose information, so remediation should not be delayed.

Affected Systems

Microsoft Windows 10 (1607, 1809, 21H2, 22H2), Microsoft Windows 11 (23H2, 24H2, 25H2, 26H1), and Microsoft Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025 (including Server Core installations) are affected by the vulnerability.

Risk and Exploitability

The CVSS score of 5.5 places this issue in the medium risk range, while the EPSS score of less than 1% and absence from the KEV catalog indicate a low probability of current exploitation. Attackers would require local, authorized access and would be exploiting the driver's cleartext transmission of data, typical of a local information disclosure scenario. Given the limited exploitation likelihood, the priority for mitigation is to apply the official Microsoft update and assess application use of the driver.

Generated by OpenCVE AI on July 31, 2026 at 09:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft Windows update that addresses CVE-2026-34346 to all affected Windows 10, 11 and Server editions.
  • If the ancillary function driver is not required for your environment, remove or disable it to eliminate the cleartext exposure.
  • Review local application logs for any abnormal WinSock traffic that might indicate exploitation, and enforce strict access controls for components that use the driver.

Generated by OpenCVE AI on July 31, 2026 at 09:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Description Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally.
Title Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft windows 10 1607
Microsoft windows 10 1809
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2012
Microsoft windows Server 2012 R2
Microsoft windows Server 2016
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
Weaknesses CWE-319
CPEs cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_21H2:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_22H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_23H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_23H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2012:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2012_R2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 10 1607
Microsoft windows 10 1809
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2012
Microsoft windows Server 2012 R2
Microsoft windows Server 2016
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 10 1607 Windows 10 1809 Windows 10 21h2 Windows 10 22h2 Windows 11 23h2 Windows 11 24h2 Windows 11 25h2 Windows 11 26h1 Windows Server 2012 Windows Server 2012 R2 Windows Server 2016 Windows Server 2019 Windows Server 2022 Windows Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-03T22:52:48.311Z

Reserved: 2026-03-26T21:02:16.446Z

Link: CVE-2026-34346

cve-icon Vulnrichment

Updated: 2026-07-15T13:23:44.089Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T10:00:05Z

Weaknesses
  • CWE-319

    Cleartext Transmission of Sensitive Information