Executive brief
A security vulnerability exists in a core Windows networking component that handles socket connections. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to bypass security restrictions, access sensitive data, or install malicious software.
Technical details
A use-after-free vulnerability exists in the Windows Ancillary Function Driver (afd.sys) for WinSock. The flaw is rooted in a race condition (CWE-362) during concurrent execution using shared resources with improper synchronization. To exploit this, an attacker must first have local access to the system with low-level privileges. Successful exploitation allows the attacker to execute code with SYSTEM privileges, leading to a complete compromise of the host's confidentiality, integrity, and availability.
Affected products
- Microsoft Windows
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory