CVE-2026-61348
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Description
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
In plain language
AI Act nowThis Windows local vulnerability can let a low-privileged attacker gain full control of the computer by triggering a memory mistake in the WinSock-related driver; if you’re running affected Windows and haven’t installed the listed updates, you should act.
CVE-2026-61348 is a local privilege escalation (CWE-416) in the Windows Ancillary Function Driver for WinSock, where a memory error (use after being deleted) allows a low-privileged, locally authenticated attacker to elevate to full administrative/kernel-level access.
What to do now
- Check which of the affected Windows versions you run and confirm your patch level (Windows Update “View update history” or your IT inventory).
- Upgrade/patch each system to the fixed version for your specific Windows release:
- Re-check after updating to ensure the target fixed build is actually installed.
- If patching can’t be completed right away, restrict local logons and remove unnecessary low-privilege accounts so fewer users can attempt local exploitation.
CVSS Vector Breakdown
AV:LAttack VectorAC:HAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilitiesen·Cisco Talos· Exploited Windows patch-tuesday
- Microsoft Patch Tuesday, August 2026 Security Update Reviewen-us·Qualys Security Blog· Exploited Windows patch-tuesday
- Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-daysen-us·BleepingComputer· Exploited Windows Lazarus group
- Microsoft Patch Tuesday August 2026 - SANS ISCen·SANS Internet Storm Center· Exploited Windows zero-day
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-61348 and every CVE in our database. Create a free account — no credit card required.
Create Free Account