CVE-2026-26168

7.8

Microsoft · Windows Ancillary Function Driver for WinSock

A race condition vulnerability in the Windows Ancillary Function Driver for WinSock allows local, authenticated attackers to achieve privilege escalation.

Executive summary

A race condition vulnerability in the Windows Ancillary Function Driver for WinSock allows an authenticated attacker to elevate privileges to the system level.

Vulnerability

This vulnerability is a race condition (CWE-362) within the Windows Ancillary Function Driver for WinSock, which may also involve a use after free (CWE-416). An authenticated attacker with local access can exploit this flaw to execute code with elevated privileges.

Business impact

Successful exploitation of this vulnerability allows a local user to gain unauthorized administrative control over the affected system. Given the CVSS score of 7.8, this represents a high-severity risk that could lead to complete system compromise, data exfiltration, or the installation of persistent malicious software.

Remediation

Immediate Action: Apply the relevant security updates provided by Microsoft in the official update guide to address the underlying race condition.

Proactive Monitoring: Monitor system logs for unusual process execution patterns or unexpected privilege changes associated with local user accounts.

Compensating Controls: Ensure that strict access controls are enforced on local endpoints to limit the number of users with local login capabilities, thereby reducing the potential attack surface.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Organizations should prioritize the deployment of the identified security patches across all affected Windows versions. As privilege escalation flaws are frequently targeted by threat actors to expand access within a network, immediate remediation is necessary to maintain system integrity and security.

More Microsoft CVEs

Sources