CVE-2025-21418CISA KEV
Microsoft Windows Ancillary Function Driver for WinSock Heap-Based Buffer Overflow Vulnerability
CISA lists this Microsoft vulnerability as known exploited. Its MSRC release detail is outside this installation's collected history.
CISA catalog record
Microsoft Windows Ancillary Function Driver for WinSock contains a heap-based buffer overflow vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges.
- Product
- Windows
- Added to KEV
- 11 Feb 2025
- Federal remediation due
- 4 Mar 2025
- Known ransomware use
- Not reported