Executive brief
A use-after-free vulnerability in the Microsoft Windows Ancillary Function Driver (AFD) for WinSock allows a locally authenticated attacker to escalate privileges to Administrator. The flaw was also described as a null pointer dereference in some documentation updates.
Affected products
- Microsoft Windows 10 up to (excluding) 10.0.19045.5854
- Microsoft Windows 11 up to (excluding) 10.0.26100.4061
- Microsoft Windows Server 2012 All
- Microsoft Windows Server 2016 up to (excluding) 10.0.14393.8066
- Microsoft Windows Server 2019 up to (excluding) 10.0.17763.7314
- Microsoft Windows Server 2022 up to (excluding) 10.0.20348.3692
- Microsoft Windows Server 2025 up to (excluding) 10.0.26100.4061
Timeline
- 2025-05-13: disclosed
- 2025-05-13: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2025-05-13: exploited: Reported as exploited in the wild at time of publication.