ZeroHour

CVE-2026-70342

mass

Use-after-free in Windows Winsock AFD driver enables network privilege escalation

CVSS 3.1
8.1 high
EPSS
<1%p57
Published
()
Modified
AI analysis

Use-after-free (CWE-416) in the Windows Ancillary Function Driver for Winsock (AFD, afd.sys) — the kernel-mode driver behind the Windows socket API — can be triggered over a network, allowing an unauthorized attacker to elevate privileges on the affected system. The CVSS vector (AV:N/AC:H/PR:N/UI:N) indicates a network-reachable flaw requiring no credentials or user interaction but with high attack complexity, consistent with a timing/race condition on socket handle reuse. Successful exploitation carries high impact across confidentiality, integrity, and availability, most plausibly yielding kernel- or SYSTEM-level privilege elevation and full host compromise. Every Windows installation shipping the affected AFD driver is in scope, although the provided data does not include Microsoft's exact affected version ranges. Exploitation status: none known in the wild, no public proof-of-concept, no CISA KEV listing, and EPSS estimates roughly a 0.9% chance of exploitation within 30 days (57th percentile).

What to do: Apply Microsoft's security update for CVE-2026-70342 to Windows clients and servers promptly once released, prioritizing internet-exposed hosts and multi-user or shared Windows systems. The available data documents no workaround, so in the interim minimize network exposure of Windows hosts, ensure the AFD driver and Winsock-related event logs are monitored for anomalies, and track Microsoft's advisory for the exact affected version ranges.

Affected
Microsoft Windows Ancillary Function Driver for Winsock (AFD / afd.sys)
Estimated exposure
mass≈1B+ Windows installations (AFD ships with every Windows client and server) — AFD is a core kernel driver present in essentially all Windows deployments, so the potentially affected population spans the entire Windows installed base; actual exploitable-and-reachable systems are an unknown subset of that, better…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Ancillary Function Driver for WinSock allows an unauthorized attacker to elevate privileges over a network.

Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.