Junglewise Threat Intelligence

CVE-2025-32709: Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability

CVE-2025-32709 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2025-05-13

Technologies: Microsoft Windows, Microsoft Windows Server 2019, Microsoft Windows Server 2016, Microsoft Windows 11, Microsoft Windows Server 2022, Microsoft Windows Server 2025, Microsoft Windows Server 2012, Microsoft Windows 10. Vendors: Microsoft.

Executive brief

A use-after-free vulnerability in the Microsoft Windows Ancillary Function Driver (AFD) for WinSock allows a locally authenticated attacker to escalate privileges to Administrator. The flaw was also described as a null pointer dereference in some documentation updates.

Affected products

  • Microsoft Windows 10 up to (excluding) 10.0.19045.5854
  • Microsoft Windows 11 up to (excluding) 10.0.26100.4061
  • Microsoft Windows Server 2012 All
  • Microsoft Windows Server 2016 up to (excluding) 10.0.14393.8066
  • Microsoft Windows Server 2019 up to (excluding) 10.0.17763.7314
  • Microsoft Windows Server 2022 up to (excluding) 10.0.20348.3692
  • Microsoft Windows Server 2025 up to (excluding) 10.0.26100.4061

Timeline

  • 2025-05-13: disclosed
  • 2025-05-13: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2025-05-13: exploited: Reported as exploited in the wild at time of publication.

Related threats