CVE-2025-32709
KEVmassLocal Privilege Escalation (Use-After-Free) in Windows WinSock AFD Driver
CISA: Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
CVE-2025-32709 is a memory-safety flaw in the Windows Ancillary Function Driver for WinSock (afd.sys), the kernel-mode driver that implements Windows sockets; CISA classifies it as a use-after-free (CWE-416) while Microsoft's description calls it a null pointer dereference. A local, authenticated attacker triggers the flaw through the WinSock driver, with no user interaction or network access required. Successful exploitation elevates the attacker from low privileges to kernel/SYSTEM-level access, giving full control of the host. Any system running the listed Windows 10, Windows 11, or Windows Server versions carries the vulnerable driver, which covers the vast majority of enterprise Windows fleets. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2025-05-13 as one of the actively exploited zero-days in Microsoft's May 2025 Patch Tuesday release; no public PoC is known and ransomware use is unconfirmed.
What to do: Install the Microsoft security update for CVE-2025-32709 from Microsoft's monthly cumulative updates following the May 13, 2025 disclosure on every affected Windows 10/11 and Windows Server host, prioritizing servers and workstations that allow interactive logon by low-privileged users. Because the flaw is on CISA's KEV catalog, federal agencies must apply the update or vendor-directed mitigations under BOD 22-01. Until patched, restrict local logon rights on Windows servers to trusted accounts and review event logs for suspicious process creations by standard users that indicate privilege-escalation activity.
| Microsoft Windows 10 1507 | 1507 |
| Microsoft Windows 10 1607 | 1607 |
| Microsoft Windows 10 1809 | 1809 |
| Microsoft Windows 10 21H2 | 21H2 |
| Microsoft Windows 10 22H2 | 22H2 |
| Microsoft Windows 11 22H2 | 22H2 |
| Microsoft Windows 11 23H2 | 23H2 |
| Microsoft Windows 11 24H2 | 24H2 |
| Microsoft Windows Server 2008 | 2008 |
| Microsoft Windows Server 2012 | 2012 |
| Microsoft Windows Server 2016 | 2016 |
| Microsoft Windows Server 2019 | 2019 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
- Affected
- Microsoft Windows
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 22h2, windows 11 23h2, windows 11 24h2, windows server 2008, windows server 2012, windows server 2016, windows server 2019
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H