Impact
The vulnerability is a race condition caused by concurrent execution using a shared resource with improper synchronization in the Windows Ancillary Function Driver for WinSock. An authorized local attacker can manipulate the driver’s state to elevate privileges on the system.
Affected Systems
The flaw applies to Microsoft Windows 10 releases 1607, 1809, 21H2 and 22H2; Windows 11 releases 23H2, 24H2, 25H2, 26H1; and Windows Server editions 2012, 2012 R2, 2016, 2019, 2022 and 2025, in both full and core installations. All supported architectures—x86, x64, and arm64—are affected.
Risk and Exploitability
The CVSS score of 7 signifies medium severity. The EPSS score of < 1% indicates a very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local and requires the attacker to have a user account with local privileges to exploit the race condition in the Windows Ancillary Function Driver for WinSock. The vulnerability could allow privilege escalation if the attacker can manipulate the shared resource state from their local session.
OpenCVE Enrichment