Impact
Use‑after‑free in the Windows Ancillary Function Driver for WinSock allows a local attacker with authorization to gain higher privileges. The flaw occurs when the driver deallocates memory that remains referenced, enabling the attacker to manipulate kernel data structures to execute arbitrary code or elevate privilege. This can compromise confidentiality, integrity and availability of the affected system by permitting the attacker to run code with elevated rights.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1; Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, including Server Core installations.
Risk and Exploitability
The CVSS score of 7 indicates a high‑medium severity flaw, and the EPSS score of 6% implies low exploitation probability at present. The vulnerability is listed in the CISA KEV catalog, signifying that there have been known or suspected exploits in the wild. Exploitation requires a local authenticated user who can trigger the WinSock driver, and the attacker must target the specific use‑after‑free condition in the Ancillary Function Driver to elevate privileges. The flaw is a classic use‑after‑free (CWE‑416) and can lead to arbitrary code execution at a higher privilege level once the attack is successful.
OpenCVE Enrichment