CVE-2026-34344 is a local privilege escalation vulnerability in the Windows Ancillary Function Driver for WinSock (afd.sys). The flaw is caused by type confusion, where the driver accesses a resource using an incompatible type while handling user-reachable networking functionality. An authenticated local attacker with low privileges can trigger the bug, likely through crafted socket operations or I/O control interactions that cause afd.sys to misinterpret internal kernel data structures. Successful exploitation can corrupt kernel memory and enable modification of security-sensitive kernel objects, resulting in elevation of privilege to SYSTEM. The vulnerability affects multiple supported Windows client and server releases prior to Microsoft's May 12, 2026 security updates.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This is a two-file standalone Windows C++ crash PoC, not a framework module. `crash/head.hpp` defines packed representations of an AFD open packet and EA header, plus an NtCreateFile function-pointer type. `crash/poc.cpp` is the executable entry point. It first uses DefineDosDeviceW with DDD_RAW_TARGET_PATH to map the local alias `abc` to `\\Device\\Afd`. It then builds a binary EA buffer named `AfdOpenPacketXX`, containing AF_INET, SOCK_STREAM, and TCP protocol fields and the transport path `\\??\\abc\\Endpoint`. Finally, it dynamically resolves NtCreateFile from ntdll.dll and submits the EA while opening `\\Device\\Afd\\Endpoint`. The apparent purpose is to exercise a malformed or unusual AFD endpoint-creation path and cause a local system/driver crash (denial of service). No network connection is made despite the AF_INET/TCP fields; those fields describe the requested AFD socket endpoint. There is no CVE identifier, version constraint, remote target, persistence mechanism, command execution, or post-exploitation payload in the supplied code.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A local privilege escalation vulnerability caused by type confusion (CWE-843) in the Windows Ancillary Function Driver for WinSock (afd.sys), allowing a low-privileged local user to corrupt kernel memory and escalate privileges to SYSTEM.
A local elevation of privilege vulnerability in the Windows Ancillary Function Driver for WinSock caused by type confusion, allowing an authorized attacker with low privileges to gain SYSTEM privileges.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.