PT-2023-1163 · Microsoft · Windows Ancillary Function Driver For Winsock+1

CVE-2023-21768

·

Published

2023-01-10

·

Updated

2026-06-25

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Windows Ancillary Function Driver for WinSock (affected versions not specified)
Description An elevation of privilege issue exists in the Windows Ancillary Function Driver for WinSock (afd.sys), which implements the kernel-side of WinSock. The flaw is caused by insufficient validation of a user-supplied pointer in an IOCTL (Input/Output Control) path, where IOCTLs are used to communicate between user-mode applications and kernel-mode drivers. This allows an attacker to create an arbitrary kernel write primitive and elevate their privileges to NT AUTHORITYSYSTEM.

Exploit

Fix

LPE

Untrusted Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-00377
CVE-2023-21768

Affected Products

Windows
Windows Ancillary Function Driver For Winsock