Impact
The flaw is a race condition in the Windows Ancillary Function Driver for WinSock. When multiple operations access driver data concurrently without proper synchronization, an authorized local user can manipulate the driver’s state to achieve higher privileges on the system. This concurrent execution leads to privilege escalation.
Affected Systems
The flaw applies to Microsoft Windows 10 releases 1607, 1809, 21H2 and 22H2; Windows 11 releases 23H2, 24H2, 25H2, 26H1; and Windows Server editions 2012, 2012 R2, 2016, 2019, 2022 and 2025, in both full and core installations. All supported architectures—x86, x64, and arm64—are affected.
Risk and Exploitability
The CVSS score of 7 signifies a medium severity assessment. The EPSS score of < 1 % indicates a very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local and requires an authenticated user or physical access; this inference comes from the description stating the vulnerability can be exploited by an authorized local attacker. No public exploit is known, and attacks would need to be performed from a user account with local privileges on the target system.
OpenCVE Enrichment