Junglewise Threat Intelligence

CVE-2026-34344: Microsoft Windows type confusion in Ancillary Function Driver for WinSock

CVE-2026-34344 · Severity: high · CVSS 7.8 · Published 2026-05-12

Technologies: Microsoft Windows Ancillary Function Driver for WinSock. Vendors: Microsoft.

Executive brief

A security vulnerability exists in a core Windows networking component responsible for managing socket connections. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative or system-level control. This could allow them to bypass security restrictions, access sensitive data, or install malicious software across the entire operating system.

Technical details

This vulnerability is classified as a type confusion (CWE-843) within the Windows Ancillary Function Driver for WinSock (afd.sys). The flaw occurs when the driver improperly handles objects in memory, allowing an attacker to supply a specifically crafted input that causes the driver to access a resource using an incompatible type. To exploit this, an attacker must first have local execution privileges on the target system. Successful exploitation allows the attacker to execute code with elevated privileges, typically SYSTEM, leading to a full compromise of the host's integrity and confidentiality. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Windows Ancillary Function Driver for WinSock (afd.sys)

Timeline

  • 2026-05-12: disclosed: Initial disclosure by Microsoft and NVD.
  • 2026-05-12: advisory: Microsoft MSRC advisory published.

References

Related threats