Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

Microsoft Windows Ancillary Function Driver for WinSock Privilege Escalation Vulnerability

Vulnerability

A use-after-free vulnerability has been identified in the Windows Ancillary Function Driver for WinSock. This vulnerability allows an authorized attacker to locally elevate privileges. It affects several different versions and ranges of Windows Server 2008 and Windows Server 2008 R2.

Impact

Exploitation of this vulnerability could lead to unauthorized privilege escalation, allowing an attacker to gain administrator rights.

Remediation

To address this vulnerability, users should install the Out-of-Band (OOB) updates released on May 13, 2025. These updates are cumulative, so if the May 2025 monthly rollup or security-only updates have already been installed, the OOB updates must also be applied. The specific OOB update to install depends on the version of Windows Server 2008 or 2008 R2 in use.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
8.1
impact
7.5
exploitability
5.2
remediation
7.7
relevance
0.0
threat
8.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.