CVE-2026-70565
massUse-After-Free Local Privilege Elevation in Windows AF_UNIX Socket Provider
Windows' AF_UNIX Socket Provider contains a use-after-free vulnerability (CWE-416), tracked as CVE-2026-70565 and assigned by Microsoft. A local, authenticated low-privileged attacker ('authorized attacker') can trigger the flaw through operations against AF_UNIX sockets, freeing memory that is still in use; the high attack complexity (AC:H) indicates the triggering conditions are narrow and exploitation may not be reliably repeatable. Successful exploitation elevates the attacker's privileges locally, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 7.0). Any Windows system carrying the AF_UNIX socket provider is in scope, though the precise affected version ranges are given in Microsoft's advisory rather than in this data. There is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.3% probability of exploitation within 30 days (17th percentile).
What to do: Apply Microsoft's security update for CVE-2026-70565 via Windows Update when available, prioritizing multi-user hosts (RDS/session servers, shared workstations, CI runners) where untrusted users hold local accounts. Until patched, restrict local logon and code-execution rights on sensitive systems, since the flaw requires an authorized local user to trigger. Check Microsoft's advisory for the exact affected Windows versions, which are not enumerated in the provided data.
| Microsoft Windows (AF_UNIX Socket Provider) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows AF_UNIX Socket Provider allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.