PT-2023-1163 · Microsoft · Windows Ancillary Function Driver For Winsock+1
CVE-2023-21768
·
Published
2023-01-10
·
Updated
2026-06-25
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Windows Ancillary Function Driver for WinSock (affected versions not specified)
Description
An elevation of privilege issue exists in the Windows Ancillary Function Driver for WinSock (
afd.sys), which implements the kernel-side of WinSock. The flaw is caused by insufficient validation of a user-supplied pointer in an IOCTL (Input/Output Control) path, where IOCTLs are used to communicate between user-mode applications and kernel-mode drivers. This allows an attacker to create an arbitrary kernel write primitive and elevate their privileges to NT AUTHORITYSYSTEM.Exploit
Fix
LPE
Untrusted Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Windows
Windows Ancillary Function Driver For Winsock