Important CVSS 7 EPSS 0.02491 🔬 Patch diffed 2026-02 archive

Executive Summary

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Overview

7
CVSS HIGH
Important
MS Severity
Not Exploited
MS Exploit Status
More Likely
MS Exploit Likelihood
Category Elevation of Privilege
Released Feb 10 2026
Last Updated Feb 10 2026
Publicly Disclosed No
CISA KEV Not Listed
Known Exploits None Known
EPSS Score 0.02491 — 0.83221 percentile
NVD CVSS 7 HIGH — matches MSRC

CVSS Vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
ATTACK VECTOR
Local
ATTACK COMPLEXITY
High
PRIVILEGES REQUIRED
Low
USER INTERACTION
None
SCOPE
Unchanged
CONFIDENTIALITY
High
INTEGRITY
High
AVAILABILITY
High
EXPLOIT CODE MATURITY
Unproven
REMEDIATION LEVEL
Official Fix
REPORT CONFIDENCE
Confirmed
Temporal Score: 6.1

EPSS Score

0.02491
probability of exploitation in the next 30 days
0.83221 percentile - updated 2026-08-14
View on FIRST.org

Affected Products

5 affected products
Product KB Article Severity Impact Restart Required
Windows 11 Version 23H2 for ARM64-based Systems 5075941 (Security Update) Important Elevation of Privilege Yes
Windows 11 Version 23H2 for x64-based Systems 5075941 (Security Update) Important Elevation of Privilege Yes
Windows 11 Version 24H2 for ARM64-based Systems 5077181 (Security Update) 5077212 (Security Hotpatch Update) Important Elevation of Privilege 5073379 Base: 7.0 Temporal: 6.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26100.7840 10.0.26100.7781 Yes None Windows 11 Version 24H2 for x64-based Systems 5077212 (Security Hotpatch Update) 5077181 (Security Update) Important Elevation of Privilege 5074109 Base: 7.0 Temporal: 6.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26100.7781 10.0.26100.7840 Yes None Windows 11 Version 25H2 for ARM64-based Systems 5077181 (Security Update) 5077212 (Security Hotpatch Update) Important Elevation of Privilege 5074109 Base: 7.0 Temporal: 6.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26200.7840 10.0.26200.7781 Yes None Windows 11 Version 25H2 for x64-based Systems 5077181 (Security Update) 5077212 (Security Hotpatch Update) Important Elevation of Privilege 5074109 Base: 7.0 Temporal: 6.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26200.7840 10.0.26200.7781 Yes None Windows 11 Version 26H1 for ARM64-based Systems 5077179 (Security Update) Important Elevation of Privilege Yes
Windows 11 version 26H1 for x64-based Systems 5077179 (Security Update) Important Elevation of Privilege Yes
Windows Server 2022 5075906 (Security Update) 5075943 (Security Hotpatch Update) Important Elevation of Privilege 5073457 Base: 7.0 Temporal: 6.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.20348.4773 10.0.20348.4711 Yes None Windows Server 2022 (Server Core installation) 5075906 (Security Update) 5075943 (Security Hotpatch Update) Important Elevation of Privilege 5073457 Base: 7.0 Temporal: 6.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.20348.4773 10.0.20348.4711 Yes None Windows Server 2022, 23H2 Edition (Server Core installation) 5075897 (Security Update) Important Elevation of Privilege Yes

Patches

3 patches
Article Type Restart
5075941 Security Update Yes
5077179 Security Update Yes
5075897 Security Update Yes

Patch Diff

ghidriff · afd.sys (KB5077181)

Patch diff 10.0.26100.7623 -> 10.0.26100.7824

Pre-patch version 10.0.26100.7623 Download
Post-patch version 10.0.26100.7824 Download
Function Address Change Note
AfdBReceive 14003f640 -> 14003e810 code, length, address, called similarity 0.63
NTOSKRNL.EXE::MmMapLockedPages EXTERNAL:000000d5 -> EXTERNAL:000000d6 refcount, address similarity 1.0
AfdNotifyPostEvents 14005364c -> 140053cac code, length, address, called similarity 0.39
memcpy 140074980 -> 140075200 refcount, address similarity 1.0
AfdFastDatagramReceive 140033850 -> 140032940 code, length, address, called similarity 0.6
AfdTdiCreateAO 14002c650 -> 14002b6a0 code, length, sig, address, called similarity 0.92
AfdNotifyDestroyContext 14005349c -> 140053adc code, length, address, called similarity 0.67
AfdCleanupCore 140013870 -> 1400135a0 code, length, address, called similarity 0.67
AfdTransmitPackets 140043d30 -> 140044100 code, length, address, called similarity 0.41
AfdBCommonChainedReceiveEventHandler 14001a380 -> 140019340 code, length, address, called similarity 0.98
AfdSuperAccept 14002a310 -> 140029300 code, length, address, called similarity 0.26
AfdSanConnectHandler 14005c570 -> 14005cc50 code, length, address, called similarity 0.29
AfdRestartSuperAcceptGetAddress 14004a7e0 -> 14004ae30 code, length, address, called similarity 0.98
AfdCloseCore 140006ac8 -> 1400150c0 code, length, address, called similarity 0.17
wil_details_IsEnabledFallback 14004b4c8 -> 14004bab4 refcount, address, calling similarity 1.0
AfdReceiveDatagram 14003dec0 -> 14003d010 code, length, address, called similarity 0.67
AfdSanAcceptCore 140044f40 -> 1400453bc code, length, address, called similarity 0.19
__security_check_cookie 140074850 -> 1400750c0 refcount, address, calling similarity 1.0
AfdNotifyProcessRegistration 14005390c -> 140053fb8 code, length, address, called similarity 0.48
AfdExtractAfdSendMsgInfo 1400422a0 -> 1400415b0 code, length, address, called similarity 0.41
__C_specific_handler 140049fdd -> 14004a62d refcount, address similarity 0.89
AfdCompleteBufferedSendsUnlock 140005230 code, length, called similarity 0.48
AfdFastConnectionSend 140032e60 -> 140031ef0 code, length, address, called similarity 0.7
AfdFastConnectionReceive 140031ef0 -> 140030f00 code, length, address, called similarity 0.5
__GSHandlerCheck_SEH 1400747b4 -> 140075024 refcount, address similarity 1.0
NTOSKRNL.EXE::ExFreePoolWithTag EXTERNAL:000000f5 -> EXTERNAL:000000f6 refcount, address, calling similarity 1.0
AfdQueryHandles 14003a350 -> 140039510 code, length, sig, address, called similarity 0.63
AfdBind 14002acb0 -> 140029c70 code, length, address, called similarity 0.1
AfdFastDatagramSend 140034280 -> 1400333d0 code, length, address, called similarity 0.41
Feature_2829529401__private_IsEnabledDeviceUsageNoInline 14004acf0 -> 14004c900 name, fullname, refcount, sig, address, calling, called similarity 0.71
Feature_447951161__private_IsEnabledDeviceUsageNoInline 14004acf0 -> 14004d200 name, fullname, refcount, sig, address, calling, called similarity 0.71
Feature_TCPIP_2025_Wave4_AfdTransmit_MSRC__private_IsEnabledDeviceUsageNoInline 14004acf0 -> 14005bd78 name, fullname, refcount, sig, address, calling, called similarity 0.71
Feature_3923194169__private_IsEnabledDeviceUsageNoInline 14004acf0 -> 140060620 name, fullname, refcount, sig, address, calling, called similarity 0.71
Feature_2829529401__private_IsEnabledDeviceUsageNoInline 14004c310 -> 14004c900 name, fullname, refcount, sig, address, calling, called similarity 0.71
Feature_447951161__private_IsEnabledDeviceUsageNoInline 14004c310 -> 14004d200 name, fullname, refcount, sig, address, calling, called similarity 0.71
Feature_TCPIP_2025_Wave4_AfdTransmit_MSRC__private_IsEnabledDeviceUsageNoInline 14004c310 -> 14005bd78 name, fullname, refcount, sig, address, calling, called similarity 0.71
Feature_3923194169__private_IsEnabledDeviceUsageNoInline 14004c310 -> 140060620 name, fullname, refcount, sig, address, calling, called similarity 0.71
Feature_447951161__private_IsEnabledDeviceUsageNoInline 140056c40 -> 14004d200 name, fullname, refcount, sig, address, calling, called similarity 0.71
Feature_3923194169__private_IsEnabledDeviceUsageNoInline 140056c40 -> 140060620 name, fullname, refcount, sig, address, calling, called similarity 0.71
View full diff report View RCA report Download PoC

Attack Path

A socket-notification completion packet is freed while still enqueued, then dereferenced on dequeue

Attack path for CVE-2026-21241 A socket-notification completion packet is freed while still enqueued, then dereferenced on dequeue 01 — ENTRY Local low-privileged user registers an IOCP for socket state notifications ProcessSocketNotifications (build 20348+) lets a user program register an I/O completion port to receive socket state-change events. MSRC: 'Exploitation More Likely'. 02 — CONTROLLED INPUT AfdNotifyPostEvents queues a mini-completion packet with NotifyStatus == 0 afd.sys posts events as I/O mini-completion packets carrying a NotifyStatus field. When the operation's IoStatusInformation == 0, the enqueued packet legitimately carries NotifyStatus == 0. 03 — PATH Closing the last socket handle triggers IRP_MJ_CLEANUP -> AfdNotifyDestroyContext Teardown runs while the packet may still be enqueued on the IOCP and a ProcessSocketNotifications IOCTL may still be running on another thread. 04 — MISSING CHECK DestroyContext frees the packet without cancelling it when NotifyStatus == 0 It only calls IoCancelMiniCompletionPacket when NotifyStatus != 0; with NotifyStatus == 0 it skips cancellation and ExFreePoolWithTag's the still-enqueued packet - violating the 'don't free before dequeue' rule (CWE-416, race CWE-362). 05 — PRIMITIVE Use-after-free on the freed packet at dequeue -> SYSTEM A later dequeue (GetQueuedCompletionStatus, or AfdNotifyRemoveIoCompletion on the other thread) dereferences the freed pool packet, groomable via standard pool reuse. The Feb 2026 fix removes the unconditional free in AfdNotifyDestroyContext, gated behind Feature_447951161.

Derived from the patch delta: the checks added by the vendor identify which fields crossed a trust boundary unvalidated. Reachability and privilege are taken from the call chain in the RCA report.

Known Exploits

Acknowledgments