Product
Public Proof-of-Concept for CVE-2023-21768 Local Privilege Escalation
1 TTP 1 CVEPublic availability of multiple proof-of-concept exploits for CVE-2023-21768, a local privilege escalation vulnerability in the Windows Ancillary Function Driver (AFD), increases the risk of local users elevating processes to SYSTEM privileges.
August 2026 Microsoft Security Update Analysis
1 TTP 5 CVEsMicrosoft's August 2026 security release addresses 415 vulnerabilities, including a zero-day (CVE-2026-68820) exploited in the wild that enables local privilege escalation in the Windows Ancillary Function Driver for WinSock.
CVE-2026-41088: Windows Ancillary Function Driver for WinSock Local Privilege Escalation
2 rules 1 TTP 1 CVECVE-2026-41088 is a vulnerability in Windows Ancillary Function Driver for WinSock that allows an authorized attacker to elevate privileges locally due to external control of file name or path.
CVE-2026-35416 - Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
2 rules 1 TTP 1 CVECVE-2026-35416 is a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock, enabling a locally authorized attacker to escalate privileges.
CVE-2026-34345 - Windows Ancillary Function Driver for WinSock Race Condition Privilege Escalation
2 rules 1 TTP 1 CVECVE-2026-34345 describes a race condition vulnerability in Windows Ancillary Function Driver for WinSock, allowing an authorized attacker to elevate privileges locally.
CVE-2026-34344 - Windows Ancillary Function Driver for WinSock Type Confusion Vulnerability
2 rules 1 TTP 1 CVECVE-2026-34344 is a type confusion vulnerability in the Windows Ancillary Function Driver for WinSock, allowing an authorized local attacker to elevate privileges.