Impact
The vulnerability is a race condition in the Windows Ancillary Function Driver for WinSock, where concurrent execution of shared resources without proper synchronization allows an authorized local user to gain elevated privileges. The flaw can lead to privilege escalation that compromises system integrity and confidentiality if an attacker can influence the timing of driver execution. The weakness is classified as a concurrency error and a misuse of freed memory, matching CWE-362 and CWE-416.
Affected Systems
Affected are multiple Microsoft Windows releases, including Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; and Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, 2025, including Server Core installations. The flaw applies to both 32‑bit, 64‑bit, and ARM‑based architectures as listed in the CPE strings.
Risk and Exploitability
The CVSS score of 7.0 signals a high-severity local privilege escalation flaw. EPSS is not available, so an exact exploit probability cannot be quantified, but the lack of KEV listing indicates no publicly known exploitation. The attack vector is local; an attacker must already have authorized access to the device to trigger the race condition and exploit the driver. No additional prerequisites are specified, so the vulnerability is potentially exploitable by any privileged or local user running applications that load the WinSock Ancillary Function Driver.
OpenCVE Enrichment