Microsoft disclosed CVE-2026-25179, an elevation of privilege vulnerability in the Windows Ancillary Function Driver for WinSock (afd.sys), the kernel component that supports Windows socket operations. The issue was published through Microsoft's Security Update Guide and affects a privileged part of the Windows networking stack, meaning successful exploitation could allow an attacker to gain higher permissions on a targeted system.
The newly listed flaw aligns with Microsoft's earlier disclosure of CVE-2023-35632, which affected the same Windows Ancillary Function Driver for WinSock component and was also classified as an elevation of privilege bug. The repeated appearance of privilege-escalation vulnerabilities in afd.sys highlights continued security risk around this Windows driver and reinforces the need for organizations to prioritize Microsoft security updates for systems exposed to local compromise or post-exploitation activity.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Microsoft published a Security Update Guide entry for CVE-2026-25179, another Windows Ancillary Function Driver for WinSock elevation of privilege vulnerability.
Microsoft published security guidance for CVE-2023-35632, a Windows Ancillary Function Driver for WinSock elevation of privilege vulnerability.
2 references tracked. Mallory keeps watching after this page renders.
msrc.microsoft.com
Open sourceportal.msrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.