Executive brief
A security vulnerability exists in a core Windows networking component responsible for handling socket connections. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to bypass security restrictions, access sensitive data, or install malicious software.
Technical details
A use-after-free vulnerability exists in the Windows Ancillary Function Driver (afd.sys), which is the kernel-mode driver that supports Windows Sockets (WinSock) applications. The flaw is rooted in a race condition (CWE-362) during concurrent execution using shared resources with improper synchronization. To exploit this, an attacker must first have local access and the ability to execute code with low privileges. Successful exploitation allows the attacker to execute arbitrary code in kernel mode, leading to a full local privilege escalation (LPE) to SYSTEM. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Windows
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory