CVE-2026-45596: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
Other sources
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.28000.2269Patch KB5095051 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.26132Patch KB5094042 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.9234Patch KB5094122 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.32995Patch KB5094125 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.23228Patch KB5094041 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26200.8655Patch KB5094126 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22631.7219Patch KB5093998 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.8655Patch KB5094126 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.7417Patch KB5094127 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.8880Patch KB5094123 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.5256Patch KB5094128 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.7417Patch KB5094127
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45596?
CVE-2026-45596 has a severity rating of high, with a score of 7.
How can I mitigate CVE-2026-45596?
To mitigate CVE-2026-45596, ensure that your Windows operating system is updated with the latest security patches from Microsoft.
What systems are affected by CVE-2026-45596?
CVE-2026-45596 affects Microsoft Windows 10, Windows 11, and several versions of Windows Server including 2012, 2016, 2019, 2022, and 2025.
What type of vulnerability is CVE-2026-45596?
CVE-2026-45596 is classified as an elevation of privilege vulnerability due to a use after free condition.
Who can exploit CVE-2026-45596?
CVE-2026-45596 can be exploited by an authorized attacker who has local access to the affected system.