Impact
A use‑after‑free flaw in the Windows Ancillary Function Driver for WinSock can be exploited by an authorized local user to gain higher privileges. The driver operates at kernel level; the vulnerability allows the attacker to read or write arbitrary memory within the driver context, ultimately enabling execution of code with system rights. This results in loss of confidentiality, integrity and availability for the affected system.
Affected Systems
The vulnerability affects a broad set of Microsoft Windows operating systems, including Windows 10 from Version 1607 through 22H2, Windows 11 from 23H2 through 26H1, and Windows Server releases 2012, 2012 R2, 2016, 2019, 2022 and 2025 running either standard or core editions. The impacted component is the kernel‑mode Ancillary Function Driver for WinSock, present on x86, x64, arm64 and ARM32 architectures.
Risk and Exploitability
The CVSS score of 7 denotes high severity, and the EPSS score is 1%. The vulnerability is not listed in CISA’s KEV catalog, suggesting that no widespread exploitation has been reported yet. The attack vector is local and requires an authenticated user to run specially crafted code that triggers the use‑after‑free. Given the lack of publicly available exploit code, the risk is moderate but still warrants timely remediation.
OpenCVE Enrichment