CVE-2026-20831: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Time-of-check time-of-use (toctou) race condition in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
Other sources
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.0.6003.23717Patch KB5073700 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.8783Patch KB5073722 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.32230Patch KB5073379 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.7623Patch KB5074109 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.25398.2092Patch KB5073450 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.25868Patch KB5073698 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22631.6491Patch KB5073455 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.1.7601.28117Patch KB5073699 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.22968Patch KB5073696 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26200.7623Patch KB5074109 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.6809Patch KB5073724 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.6809Patch KB5073724 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.8276Patch KB5073723 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.4648Patch KB5073457
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20831?
The CVE-2026-20831 vulnerability is classified as an elevation of privilege vulnerability, allowing authorized users to gain higher access levels.
How do I fix CVE-2026-20831?
To fix CVE-2026-20831, apply the relevant security patches provided by Microsoft for affected Windows products.
Which versions of Windows are affected by CVE-2026-20831?
CVE-2026-20831 affects several versions of Windows including Windows Server 2008, Windows Server 2016, Windows 10, and Windows 11.
Can CVE-2026-20831 be exploited remotely?
No, CVE-2026-20831 requires local access for exploitation, as it is an elevation of privilege vulnerability.
What are the potential impacts of CVE-2026-20831 on my systems?
Exploitation of CVE-2026-20831 could allow an attacker to elevate their privileges and perform unauthorized actions on the system.