HIGH
CVE-2025-21418
CVSS
7.8
KEV
Description
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Summary dbcve.org
This is a local Elevation of Privilege vulnerability in the Windows Ancillary Function Driver (AFD), which is a kernel-mode driver responsible for Winsock operations. An authenticated local attacker could exploit this to gain elevated privileges on the affected system.
Mitigation
Apply the relevant Windows security update (KB) for this CVE through standard Windows Update or manual patch deployment. Verify the AFD driver version matches the patched version after deployment.
Weakness (CWE)
CWE-122
Heap-based Buffer Overflow
EPSS Score
1.57%
Probability of exploitation in next 30 days
73.8th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.