CVE-2026-21241Use After Free in Microsoft Windows 11 Version 22h3

CWE-416Use After Free5 documents5 sources
Severity
7.0HIGHNVD
EPSS
0.0%
top 92.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 10

Description

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.0 | Impact: 5.9

Affected Packages11 packages

NVDmicrosoft/windows< 10.0.20348.4711+2
NVDmicrosoft/windows_11_23h2< 10.0.22631.6649
NVDmicrosoft/windows_11_24h2< 10.0.26100.7781
NVDmicrosoft/windows_11_25h2< 10.0.26200.7781
CVEListV5microsoft/windows_server_202210.0.20348.010.0.20348.4773

🔴Vulnerability Details

2
CVEList
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability2026-02-10
GHSA
GHSA-3g4j-rmgh-9r5p: Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally2026-02-10

📋Vendor Advisories

1
Microsoft
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability2026-02-10

🕵️Threat Intelligence

1
Wiz
CVE-2026-21241 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2026-21241 — Use After Free in Microsoft | cvebase