Microsoft Windows Server 2008
cpe:2.3:o:microsoft:windows_server_2008:*:*:*:*:*:*:*, +2 more
This vulnerability is being actively exploited in the wild.
A use-after-free vulnerability has been identified in the Windows Ancillary Function Driver for WinSock. This vulnerability allows an authorized attacker to locally elevate privileges. It affects several different versions and ranges of Windows Server 2008 and Windows Server 2008 R2.
Exploitation of this vulnerability could lead to unauthorized privilege escalation, allowing an attacker to gain administrator rights.
To address this vulnerability, users should install the Out-of-Band (OOB) updates released on May 13, 2025. These updates are cumulative, so if the May 2025 monthly rollup or security-only updates have already been installed, the OOB updates must also be applied. The specific OOB update to install depends on the version of Windows Server 2008 or 2008 R2 in use.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.