CVE-2026-34345

HIGH

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

Title source: cna
STIX 2.1

Description

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

References (1)

Core 1
Core References
Vendor Advisory vendor-advisory patch
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34345

Scores

CVSS v3 7.0
EPSS 0.0004
EPSS Percentile 12.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-362 CWE-416
Status published
Products (30)
Microsoft/Windows 10 Version 1607 10.0.14393.0 - 10.0.14393.9140
Microsoft/Windows 10 Version 1809 10.0.17763.0 - 10.0.17763.8755
Microsoft/Windows 10 Version 21H2 10.0.19044.0 - 10.0.19044.7291
Microsoft/Windows 10 Version 22H2 10.0.19045.0 - 10.0.19045.7291
Microsoft/Windows 11 version 22H3 10.0.22631.0 - 10.0.22631.7079
Microsoft/Windows 11 Version 23H2 10.0.22631.0 - 10.0.22631.7079
Microsoft/Windows 11 Version 24H2 10.0.26100.0 - 10.0.26100.8457
Microsoft/Windows 11 Version 25H2 10.0.26200.0 - 10.0.26200.8457
Microsoft/Windows 11 version 26H1 10.0.28000.0 - 10.0.28000.2113
Microsoft/Windows Server 2016 10.0.14393.0 - 10.0.14393.9140
... and 20 more
Published May 12, 2026
Tracked Since May 12, 2026