Microsoft disclosed and fixed multiple elevation-of-privilege vulnerabilities in the Windows Ancillary Function Driver for WinSock (AFD.sys), including CVE-2026-34344 and CVE-2026-34345, which could allow a low-privileged local attacker to gain SYSTEM privileges. CVE-2026-34344 is a type confusion issue tracked as CWE-843 with a CVSS 7.8 rating, while CVE-2026-34345 involves a race condition and use-after-free weakness tracked as CWE-362 and CWE-416, with a CVSS 7.0 rating. Microsoft said both flaws require local access and no user interaction, and credited Puponia Angelboy (@scwuaptx) of DEVCORE with reporting them through coordinated disclosure.
Microsoft assessed exploitation of both newly detailed flaws as less likely and said neither had been publicly disclosed nor exploited in the wild at the time of publication. The disclosures add to a broader pattern of AFD.sys privilege-escalation fixes listed in Microsoft’s Security Update Guide, including CVE-2025-49661, CVE-2025-54099, CVE-2025-58714, CVE-2026-25176, and CVE-2026-25178, indicating continued security hardening around the Windows WinSock ancillary driver. Official patches are available through Microsoft’s security updates.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Microsoft disclosed CVE-2026-34345 as an Important Windows Ancillary Function Driver for WinSock elevation-of-privilege vulnerability involving a race condition and use-after-free. Microsoft said successful local exploitation could yield SYSTEM privileges, assessed exploitation as less likely, reported no public disclosure or in-the-wild exploitation at publication, and released a fix while crediting DEVCORE's Angelboy.
Microsoft disclosed CVE-2026-34344 as an Important Windows Ancillary Function Driver for WinSock elevation-of-privilege flaw caused by type confusion (CWE-843). The company said a low-privileged local attacker could gain SYSTEM privileges, that the bug was not publicly disclosed or exploited in the wild at publication, and that a fix was available; credit was given to DEVCORE researcher Puponia Angelboy.
Microsoft published Security Update Guide entries for CVE-2026-25178, an elevation-of-privilege vulnerability in the Windows Ancillary Function Driver for WinSock. The advisory and vulnerability pages indicate the issue was disclosed with an official fix on the same date.
Microsoft published a Security Update Guide advisory for CVE-2026-25176, an elevation-of-privilege vulnerability in the Windows Ancillary Function Driver for WinSock. No further technical synopsis was provided in the reference.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
msrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.