Junglewise Threat Intelligence

CVE-2026-70342: Microsoft Windows Ancillary Function Driver use after free privilege escalation

CVE-2026-70342 · Severity: high · CVSS 8.1 · Published 2026-09-08

Executive brief

Windows Ancillary Function Driver for WinSock is a core system component that handles low-level network operations on Windows systems. A use-after-free vulnerability in this driver allows an attacker on the network to escalate privileges without authorization, potentially gaining complete control over affected systems and compromising sensitive data or disrupting critical operations.

Technical details

This vulnerability is a use-after-free condition in the Windows Ancillary Function Driver for WinSock (AFD.sys), a kernel-mode driver responsible for Winsock socket operations. The defect occurs when a previously freed memory object is accessed, allowing an attacker to manipulate kernel memory and execute arbitrary code at elevated privilege levels. The attack is delivered over the network without requiring local access or user interaction. An attacker can exploit this to gain SYSTEM-level privileges and compromise the entire system. Microsoft has released security patches to remediate this issue.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats