CVE-2025-21418: Microsoft Windows Ancillary Function Driver for WinSock Heap-Based Buffer Overflow Vulnerability
Microsoft Windows Ancillary Function Driver for WinSock contains a heap-based buffer overflow vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges.
Other sources
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.0.6003.23117Patch KB5052072 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.1.7601.27566Patch KB5052032 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.7785Patch KB5052006 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.22417Patch KB5052042 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.25317Patch KB5052020 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.10240.20915Patch KB5052040 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.25398.1425Patch KB5051980 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22631.4890Patch KB5051989 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.3194Fixed in 10.0.26100.3107Patch KB5052105 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.5487Patch KB5051974 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22621.4890Patch KB5051989 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.5487Patch KB5051974 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.3207Fixed in 10.0.20348.3148Patch KB5052106 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.6893Patch KB5052000
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-21418?
CVE-2025-21418 has a high severity rating due to its heap-based buffer overflow vulnerability, which allows for privilege escalation.
How do I fix CVE-2025-21418?
To fix CVE-2025-21418, apply the latest security patch provided by Microsoft for the affected Windows versions.
Which versions of Windows are affected by CVE-2025-21418?
CVE-2025-21418 affects several versions of Windows, including Windows 11, various Windows Server editions, and specific builds of Windows 10.
What type of vulnerability is CVE-2025-21418?
CVE-2025-21418 is categorized as an elevation of privilege vulnerability due to a heap-based buffer overflow in the Ancillary Function Driver for WinSock.
Who is impacted by CVE-2025-21418?
Local attackers on vulnerable systems can exploit CVE-2025-21418 to gain SYSTEM privileges, making it critical for system administrators to address.