Impact
The Windows Ancillary Function Driver for WinSock contains a heap-based buffer overflow that allows an authorized attacker to elevate privileges locally CWE-122, enables a locally authenticated user to gain elevated privileges through the overflow.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; Windows Server 2012, 2012 R2, 2016, 2019, 2022, 2025, including Server Core installations.
Risk and Exploitability
The CVSS score of 7.8 indicates medium-to-high severity, while the EPSS score of less than 1% suggests a low likelihood of active exploitation at this time. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the attacker must be authenticated locally, as no remote exploitation path is documented; from that position the heap overflow can be leveraged to execute code with elevated privileges.
OpenCVE Enrichment