← back
CVE-2025-21418

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVSS 7.8 HIGHEPSS 1.5%● KEVCWE-122
Vexday Risk Score
51Attention
SSVC decision (CISA)
Act
Exploitation + impact → act immediately
CVSS 7.8EPSS 1.5%KEV simPoC Nuclei Metasploit Patch referenciado
Lifecycle
11 Feb 2025Active exploitation (CISA KEV)
11 Feb 2025Published on NVD
Recommendation: Patch as soon as possible — active exploitation confirmed.
In short

A flaw in Windows' networking driver allows a local attacker to gain higher system privileges. An authenticated user can exploit this vulnerability to run malicious code with administrator rights.

Technical detail

CWE-122 (heap-based buffer overflow) in the Windows Ancillary Function Driver for WinSock enables local privilege escalation. The vulnerability requires an authenticated local attacker to trigger a buffer overflow condition, resulting in arbitrary code execution with SYSTEM privileges.

Summary generated and translated by AI from the official description.
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →