Impact
The vulnerability is a use‑after‑free flaw in the Windows Ancillary Function Driver for WinSock that allows an attacker who has local authorization to execute code with elevated privileges. Because the driver does not correctly validate pointers after freeing, a crafted request can cause the operating system to run code in the context of a higher privileged process.
Affected Systems
Affected systems include Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 24H2, 25H2, and 26H1; and Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, in both standard and server core installations.
Risk and Exploitability
The CVSS score is 4.7, indicating a moderate severity, while the EPSS score of less than 1% shows a very low probability of exploitation at the time of analysis. The flaw is not listed in the CISA KEV catalog. The attack requires local authorization, meaning a user with valid credentials can trigger the exploit, but it does not allow remote compromise. The use‑after‑free weakness described by CWE‑416 enables the privilege escalation path when the driver mishandles memory.
OpenCVE Enrichment