Junglewise Threat Intelligence

CVE-2026-57093: Microsoft Windows Ancillary Function Driver use after free privilege escalation

CVE-2026-57093 · Severity: high · CVSS 7 · Published 2026-07-14

Technologies: Microsoft Windows Server 2012, Microsoft Windows 10, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability exists in a core Windows networking component that handles how applications communicate over a network. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to steal sensitive data, install malicious software, or disrupt business operations.

Technical details

This vulnerability is a Use-After-Free (UAF) class flaw located within the Windows Ancillary Function Driver (afd.sys), which serves as the entry point for the WinSock interface. An attacker with low-privileged local access can trigger this condition by manipulating socket objects in memory, leading to arbitrary code execution in kernel mode. While the attack requires local access, a successful exploit results in a complete compromise of the operating system's integrity and confidentiality (SYSTEM privileges). Microsoft has released security updates to address this issue across affected Windows and Windows Server versions.

Affected products

  • Microsoft Windows 10 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 24H2, 25H2, 26H1
  • Microsoft Windows Server 2012 All editions

Timeline

  • 2026-07-14: advisory: Initial disclosure by Microsoft and NVD
  • 2026-07-14: patched: Security updates made available via Microsoft Update Guide

References

Related threats