ZeroHour

CVE-2025-32709

KEVmass

Local Privilege Escalation (Use-After-Free) in Windows WinSock AFD Driver

CISA: Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability

CVSS 3.1
7.8 high
EPSS
2%p81
Published
()
KEV added
AI analysis

CVE-2025-32709 is a memory-safety flaw in the Windows Ancillary Function Driver for WinSock (afd.sys), the kernel-mode driver that implements Windows sockets; CISA classifies it as a use-after-free (CWE-416) while Microsoft's description calls it a null pointer dereference. A local, authenticated attacker triggers the flaw through the WinSock driver, with no user interaction or network access required. Successful exploitation elevates the attacker from low privileges to kernel/SYSTEM-level access, giving full control of the host. Any system running the listed Windows 10, Windows 11, or Windows Server versions carries the vulnerable driver, which covers the vast majority of enterprise Windows fleets. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2025-05-13 as one of the actively exploited zero-days in Microsoft's May 2025 Patch Tuesday release; no public PoC is known and ransomware use is unconfirmed.

What to do: Install the Microsoft security update for CVE-2025-32709 from Microsoft's monthly cumulative updates following the May 13, 2025 disclosure on every affected Windows 10/11 and Windows Server host, prioritizing servers and workstations that allow interactive logon by low-privileged users. Because the flaw is on CISA's KEV catalog, federal agencies must apply the update or vendor-directed mitigations under BOD 22-01. Until patched, restrict local logon rights on Windows servers to trusted accounts and review event logs for suspicious process creations by standard users that indicate privilege-escalation activity.

Affected
Microsoft Windows 10 15071507
Microsoft Windows 10 16071607
Microsoft Windows 10 18091809
Microsoft Windows 10 21H221H2
Microsoft Windows 10 22H222H2
Microsoft Windows 11 22H222H2
Microsoft Windows 11 23H223H2
Microsoft Windows 11 24H224H2
Microsoft Windows Server 20082008
Microsoft Windows Server 20122012
Microsoft Windows Server 20162016
Microsoft Windows Server 20192019
Estimated exposure
masshundreds of millions of endpoints (Windows' ~70% desktop OS share; the vulnerable driver ships in every listed Windows 10/11 client and Windows Server… — Windows dominates the desktop OS market (~70% share) and Windows Server is ubiquitous in enterprises, so effectively every host running the listed Windows 10/11 and Windows Server versions carries the affected afd.sys driver — an order of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 22h2, windows 11 23h2, windows 11 24h2, windows server 2008, windows server 2012, windows server 2016, windows server 2019
Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news