cbcvebase.
CVE-2025-32709
published 2025-05-13

CVE-2025-32709: Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

PriorityP181high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2025-06-03
Exploited in the wild
EPSS
1.66%
74.0th percentile
Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Affected

47 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftwindows_10_1507< 10.0.10240.2101410.0.10240.21014
microsoftwindows_10_1607< 10.0.14393.806610.0.14393.8066
microsoftwindows_10_1809< 10.0.17763.731410.0.17763.7314
microsoftwindows_10_21h2< 10.0.19044.585410.0.19044.5854
microsoftwindows_10_22h2< 10.0.19045.585410.0.19045.5854
microsoftwindows_10_version_1507>= 10.0.10240.0 < 10.0.10240.2101410.0.10240.21014
microsoftwindows_10_version_1607>= 10.0.14393.0 < 10.0.14393.806610.0.14393.8066
microsoftwindows_10_version_1809>= 10.0.17763.0 < 10.0.17763.731410.0.17763.7314
microsoftwindows_10_version_21h2>= 10.0.19044.0 < 10.0.19044.585410.0.19044.5854
microsoftwindows_10_version_22h2>= 10.0.19045.0 < 10.0.19045.585410.0.19045.5854
microsoftwindows_11_22h2< 10.0.22621.533510.0.22621.5335
microsoftwindows_11_23h2< 10.0.22631.533510.0.22631.5335
microsoftwindows_11_24h2< 10.0.26100.398110.0.26100.3981
microsoftwindows_11_version_22h2>= 10.0.22621.0 < 10.0.22621.533510.0.22621.5335
microsoftwindows_11_version_22h3>= 10.0.22631.0 < 10.0.22631.533510.0.22631.5335
microsoftwindows_11_version_23h2>= 10.0.22631.0 < 10.0.22631.533510.0.22631.5335
microsoftwindows_11_version_24h2>= 10.0.26100.0 < 10.0.26100.406110.0.26100.4061
microsoftwindows_server_2008
microsoftwindows_server_2008_r2_service_pack_1>= 6.1.7601.0 < 6.1.7601.277306.1.7601.27730
microsoftwindows_server_2008_service_pack_2>= 6.0.6003.0 < 6.0.6003.233176.0.6003.23317
microsoftwindows_server_2012
microsoftwindows_server_2012>= 6.2.9200.0 < 6.2.9200.254756.2.9200.25475
microsoftwindows_server_2012_r2>= 6.3.9600.0 < 6.3.9600.225776.3.9600.22577
microsoftwindows_server_2016< 10.0.14393.806610.0.14393.8066
microsoftwindows_server_2016>= 10.0.14393.0 < 10.0.14393.806610.0.14393.8066

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2025-32709 is a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock (afd.sys) that allows local privilege escalation to administrator; exploitation has been detected in the wild.
  • Exploitation of CVE-2025-32709 has been confirmed in the wild as of May 2025 patch cycle; treat any unexplained local privilege escalation on Windows systems involving WinSock/afd.sys as a high-priority indicator.
  • Windows Server 2008 and 2008 R2 systems require specific Out-of-Band (OOB) updates (KB5061195, KB5061196, KB5061197, KB5061198) released May 13 2025 to be protected; unpatched systems on these versions remain exploitable even after applying the standard May 2025 rollup.
  • ·The vulnerability is described as both a null pointer dereference (NVD/MSRC) and a use-after-free (CISA KEV); the CISA KEV description of use-after-free is likely more accurate for exploitation purposes, as it aligns with the 'Exploited:Yes' status and privilege escalation impact.
  • ·Windows Server 2008/2008 R2 systems that have already installed the May 2025 monthly rollup or security-only updates must ALSO install the OOB updates to be fully protected; installing only the standard May 2025 updates is insufficient for these OS versions.

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vulncheck7.8HIGH
cisa7.8HIGH
vendor_msrc7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.