Junglewise Threat Intelligence

CVE-2026-34335: Microsoft Windows Use After Free in Ancillary Function Driver for WinSock

CVE-2026-34335 · Severity: high · CVSS 7 · Published 2026-06-09

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

A security vulnerability exists in a core Windows networking component known as the Ancillary Function Driver for WinSock. This component handles network connections for the operating system. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control, potentially allowing them to steal sensitive data or install malicious software.

Technical details

This vulnerability is classified as a Use-After-Free (CWE-416) within the Windows Ancillary Function Driver (afd.sys), which serves as the entry point for the Windows Sockets (WinSock) interface. The flaw is triggered when the driver incorrectly manages memory objects during socket operations, allowing an attacker to reference memory after it has been freed. To exploit this, an attacker must have local access to the system and valid low-privileged credentials. Successful exploitation enables the attacker to execute code with elevated privileges, typically SYSTEM, though the attack complexity is rated as high, suggesting specific timing or system states are required. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Windows

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References