Impact
A use‑after‑free flaw in the Windows Ancillary Function Driver for WinSock, designated as CWE‑416, can be triggered by a local user who can influence WinSock traffic. The vulnerability allows the attacker to access driver memory after it has been freed, potentially enabling the execution of arbitrary code at kernel privilege. This can lead to elevated system rights without authorization.
Affected Systems
The flaw affects several Microsoft Windows operating systems. It is present in Windows 10 versions 1607 through 22H2, Windows 11 releases from 23H2 to 26H1, and Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025, including their Core installations. The driver runs on x86, x64, arm64, and ARM32 architectures.
Risk and Exploitability
The CVSS score is 7, indicating high severity, while the EPSS score is below 1 % and the vulnerability is not listed in CISA’s KEV catalog. Attackers must be locally authenticated to exploit the flaw, and the exploit requires specially crafted code that triggers the use‑after‑free. The risk is moderate, yet the potential for privilege escalation warrants prompt remediation.
OpenCVE Enrichment