CVE-2026-33099: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
Other sources
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.26026Patch KB5082127 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.23132Patch KB5082126 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.7184Patch KB5082200 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.9060Patch KB5082198 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.5020Patch KB5082142 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.8644Patch KB5082123 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.25398.2274Patch KB5082060 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26200.8246Patch KB5083769 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.8246Patch KB5083769 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22631.6936Patch KB5082052 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.7184Patch KB5082200
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33099?
CVE-2026-33099 is rated as a critical severity vulnerability that allows elevation of privilege.
How do I fix CVE-2026-33099?
To fix CVE-2026-33099, install the security update provided by Microsoft for your affected Windows version.
What systems are affected by CVE-2026-33099?
CVE-2026-33099 affects multiple versions of Windows, including Windows Server 2012, Windows 10, and Windows 11.
Can CVE-2026-33099 be exploited remotely?
CVE-2026-33099 requires local access to the system to exploit, meaning it cannot be exploited remotely.
What types of attacks are possible due to CVE-2026-33099?
CVE-2026-33099 can allow an authorized attacker to elevate their privileges, enabling them to perform actions normally restricted to higher-level accounts.