HIGH

CVE-2025-21418

Microsoft Windows 10 1607 2025-02-11 CVSS v3.1
CVSS
7.8
KEV

Description

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

Summary dbcve.org

This is a local Elevation of Privilege vulnerability in the Windows Ancillary Function Driver (AFD), which is a kernel-mode driver responsible for Winsock operations. An authenticated local attacker could exploit this to gain elevated privileges on the affected system.

Mitigation

Apply the relevant Windows security update (KB) for this CVE through standard Windows Update or manual patch deployment. Verify the AFD driver version matches the patched version after deployment.

Patch Commit

Weakness (CWE)

CWE-122 Heap-based Buffer Overflow

EPSS Score

1.57%
Probability of exploitation in next 30 days
73.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE