ZeroHour

CVE-2025-21418

KEVmass

Local Privilege Escalation via Heap Overflow in Windows WinSock AFD Driver

CISA: Microsoft Windows Ancillary Function Driver for WinSock Heap-Based Buffer Overflow Vulnerability

CVSS 3.1
7.8 high
EPSS
2%p74
Published
()
KEV added
AI analysis

CVE-2025-21418 is a heap-based buffer overflow (CWE-122) in the Windows Ancillary Function Driver for WinSock (AFD.sys), a kernel-mode driver that services Winsock auxiliary socket operations. A local attacker with limited user privileges can trigger the overflow by issuing crafted Winsock requests to the AFD driver, requiring no user interaction. Successful exploitation elevates the attacker's privileges on the local machine (confidentiality, integrity, and availability all impacted), which is typically used to gain SYSTEM-level control as part of a broader intrusion or ransomware chain. Any system running the affected Windows 10, Windows 11, or Windows Server releases is exposed, since the AFD driver is a core component present on all of them. The flaw was a zero-day exploited in the wild before Microsoft patched it in the February 2025 Patch Tuesday release, and CISA added it to the Known Exploited Vulnerabilities catalog on 2025-02-11.

What to do: Deploy Microsoft's February 2025 Patch Tuesday security updates for the affected Windows 10/11 and Windows Server releases immediately, prioritizing multi-user servers, jump hosts, and endpoints in ransomware-prone environments since exploitation was already active before patching. Verify deployment through your patch management/SCCM update history; there is no public PoC or known standalone mitigation, so patching is the required action per the CISA KEV entry.

Affected
Microsoft Windows 101607, 1809, 21H2, 22H2
Microsoft Windows 1122H2, 23H2, 24H2
Microsoft Windows Server 2008supported editions as listed
Microsoft Windows Server 2012supported editions as listed
Microsoft Windows Server 2016supported editions as listed
Microsoft Windows Server 2019supported editions as listed
Microsoft Windows Server 2022supported editions as listed
Estimated exposure
masson the order of 1 billion+ Windows devices (all listed Windows 10/11 client and Windows Server releases) — AFD.sys is a core kernel component on every Windows installation, and the Windows 10/11 client install base alone is widely reported at roughly a billion-plus devices, so exposure is effectively the full Windows fleet on the affected…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 22h2, windows 11 23h2, windows 11 24h2, windows server 2008, windows server 2012, windows server 2016, windows server 2019, windows server 2022
Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news