CVE-2025-21418
KEVmassLocal Privilege Escalation via Heap Overflow in Windows WinSock AFD Driver
CISA: Microsoft Windows Ancillary Function Driver for WinSock Heap-Based Buffer Overflow Vulnerability
CVE-2025-21418 is a heap-based buffer overflow (CWE-122) in the Windows Ancillary Function Driver for WinSock (AFD.sys), a kernel-mode driver that services Winsock auxiliary socket operations. A local attacker with limited user privileges can trigger the overflow by issuing crafted Winsock requests to the AFD driver, requiring no user interaction. Successful exploitation elevates the attacker's privileges on the local machine (confidentiality, integrity, and availability all impacted), which is typically used to gain SYSTEM-level control as part of a broader intrusion or ransomware chain. Any system running the affected Windows 10, Windows 11, or Windows Server releases is exposed, since the AFD driver is a core component present on all of them. The flaw was a zero-day exploited in the wild before Microsoft patched it in the February 2025 Patch Tuesday release, and CISA added it to the Known Exploited Vulnerabilities catalog on 2025-02-11.
What to do: Deploy Microsoft's February 2025 Patch Tuesday security updates for the affected Windows 10/11 and Windows Server releases immediately, prioritizing multi-user servers, jump hosts, and endpoints in ransomware-prone environments since exploitation was already active before patching. Verify deployment through your patch management/SCCM update history; there is no public PoC or known standalone mitigation, so patching is the required action per the CISA KEV entry.
| Microsoft Windows 10 | 1607, 1809, 21H2, 22H2 |
| Microsoft Windows 11 | 22H2, 23H2, 24H2 |
| Microsoft Windows Server 2008 | supported editions as listed |
| Microsoft Windows Server 2012 | supported editions as listed |
| Microsoft Windows Server 2016 | supported editions as listed |
| Microsoft Windows Server 2019 | supported editions as listed |
| Microsoft Windows Server 2022 | supported editions as listed |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
- Affected
- Microsoft Windows
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 22h2, windows 11 23h2, windows 11 24h2, windows server 2008, windows server 2012, windows server 2016, windows server 2019, windows server 2022
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H