Impact
A use‑after‑free flaw in the Windows Ancillary Function Driver for Winsock can be triggered by a local authorized user. When the freed memory is re‑used the driver may execute code with the privileges of the calling process, allowing the attacker to elevate their own privileges or perform other unauthorized actions. The weakness is a classic resource reuse vulnerability (CWE-416).
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2 and 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; and Windows Server editions from 2012 through 2025 (all core and full installations). All affected versions are listed in the official Microsoft guidance and include 32‑bit, 64‑bit, arm64 and x128 architectures where applicable.
Risk and Exploitability
The CVSS score of 7 indicates moderate to high severity. The EPSS score of less than 1% shows a very low probability of current exploitation in the wild, and the vulnerability is not yet listed in CISA’s KEV catalog. The attack requires a local user who can trigger the vulnerable driver, so it is a local privilege‑escalation vector rather than remote. Given the limited exploitation likelihood, the primary risk remains for systems that have not applied the security update and have local users with sufficient privileges.
OpenCVE Enrichment