CVE-2026-34345: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
Other sources
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
— Microsoft
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.28000.2113Patch KB5089548 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.25398.2330Patch KB5087541 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22631.7219Patch KB5093998 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.9140Patch KB5087537 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.8457Fixed in 10.0.26100.8390Patch KB5089466 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.32860Fixed in 10.0.26100.32772Patch KB5087423 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22631.7079Patch KB5087420 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.7417Patch KB5094127 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.7291Patch KB5087544 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26200.8457Fixed in 10.0.26200.8390Patch KB5089466 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.5139Fixed in 10.0.20348.5074Patch KB5087424 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.8755Patch KB5087538
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34345?
CVE-2026-34345 is classified as a critical elevation of privilege vulnerability in the Windows Ancillary Function Driver for WinSock.
How do I fix CVE-2026-34345?
To fix CVE-2026-34345, ensure your system is updated with the latest patches from Microsoft relevant to the affected products.
What products are affected by CVE-2026-34345?
CVE-2026-34345 affects several Microsoft Windows products, including Windows 10, Windows 11, and Windows Server 2016, among others.
What kind of attack can exploit CVE-2026-34345?
CVE-2026-34345 can be exploited by an authorized attacker to elevate their privileges locally through a race condition in the driver.
Are there any workarounds for CVE-2026-34345?
While installing patches is the primary recommendation, currently there are no documented workarounds for CVE-2026-34345.