Impact
An use‑after‑free condition in the Windows Ancillary Function Driver for WinSock allows an attacker who can send a specially crafted packet over the network to trigger a memory corruption that results in elevation of privilege. The flaw can be exploited remotely, giving the attacker control over the target system. The impact is the same for all affected machines because the driver runs with system privileges, so an attacker could obtain full administrative rights if they successfully execute the exploit.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; Microsoft Windows Server 2012, Server 2012 R2, Server 2016, Server 2019, Server 2022, and Server 2025 – including core installations. The vulnerability affects both x86 and x64 architectures, as well as ARM64 for certain Windows 11 releases.
Risk and Exploitability
The CVSS score of 8.1 marks this flaw as high severity. The EPSS score is not available, so the likelihood of exploitation in the wild is uncertain, but the flaw is not listed in CISA’s KEV catalog. The attack vector is inferred to be remote over the network, as the vulnerable driver processes incoming WinSock packets. An attacker would need to send a malformed packet that triggers the use‑after‑free, potentially resulting in system‑level privilege escalation if the driver fails to clean up memory correctly.
OpenCVE Enrichment