Impact
A use-after-free condition in the Windows Ancillary Function Driver for WinSock allows an attacker who has local authorization to gain privileges higher than their current session. The flaw occurs when the driver accesses memory after it has been freed, potentially allowing the attacker to execute code with a higher privilege level. This vulnerability is recorded as a local privilege escalation flaw (CWE-416).
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Microsoft Windows 11 versions 24H2, 25H2, 26H1; Microsoft Windows Server 2012 (including Server Core), 2012 R2 (including Server Core), 2016, 2016 Server Core, 2019, 2019 Server Core, 2022, 2025 (including Server Core).
Risk and Exploitability
The CVSS score of 7.0 indicates high severity, but the EPSS score of less than 1% shows that exploitation is currently unlikely in the wild, and the issue is not listed in CISA's KEV catalog. The attack requires local authorization; an attacker with sufficient local access can trigger the use-after-free to elevate privileges. No public exploits have been reported at this time.
OpenCVE Enrichment