CVE-2026-21241Disclosure(microsoft / windows_11_23h2)

LOWCVSS 7.0 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch microsoft windows_11_23h2 systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

2.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_11_23h2
  • windows_11_24h2
  • windows_11_25h2
  • windows_server_2022

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 11 mentions across 10 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 7 signals
  • Disclosure: 6 classified signals
  • Peaked 9d ago at 2 mentions (2026-02-10); latest day: 1
  • 11 total mentions across 10 days

Affected systems

Vendors
Products
windows_11_23h2windows_11_24h2windows_11_25h2windows_server_2022windows_server_2022_23h2windows_server_2025

Deep dive

Activity timeline11 mentions / 10d
01122Mentions · 2026-02-10: 2Mentions · 2026-02-11: 1Mentions · 2026-02-19: 1Mentions · 2026-02-20: 1Mentions · 2026-02-22: 1Mentions · 2026-02-24: 1Mentions · 2026-02-25: 1Mentions · 2026-03-16: 1Mentions · 2026-06-15: 1Mentions · 2026-09-13: 1PoC Mentioned / Linked · 2026-02-19: 1PoC Mentioned / Linked · 2026-02-24: 1PoC Mentioned / Linked · 2026-09-13: 1Patch / Workaround · 2026-02-10: 1Patch / Workaround · 2026-02-19: 1Patch / Workaround · 2026-02-24: 1Patch / Workaround · 2026-03-16: 1Technical Details · 2026-02-10: 2Technical Details · 2026-02-19: 1Technical Details · 2026-02-20: 1Technical Details · 2026-02-22: 1Technical Details · 2026-03-16: 1Technical Details · 2026-06-15: 102-1002-1102-1902-2002-2202-2402-2503-1606-1509-13
Signal classification4 categories
Disclosure
654.5%
Patch
218.2%
PoC
218.2%
General
19.1%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-02-102
Disclosure1Patch1
2026-02-111
Disclosure1
2026-02-191
Disclosure1
2026-02-201
Disclosure1
2026-02-221
Disclosure1
2026-02-241
PoC1
2026-02-251
General1
2026-03-161
Patch1
2026-06-151
Disclosure1
2026-09-131
PoC1
Full discourse11 posts
  • jle-k@_jle_k
    PoC

    Launched my blog with a quick exploit for CVE-2026-21241. Huge thanks to @Dark_Puzzle for finding the bug and @Bad_Jubies for diffing the patch. https://jle-k.com/blog/Exploiting+CVE-2026-21241 https://t.co/ySKTWwMOlT

    Post summary

    The author launched a blog featuring a quick exploit for CVE-2026-21241, acknowledging contributors and referencing a patch.

    448119110535.4K
    142 followersView on X
  • Bad_Jubies@Bad_Jubies
    Disclosure

    I made a write up diffing and triggering a use after free vulnerability in AFD.sys that was fixed in this month’s patch Tuesday: https://bad-jubies.github.io/cve-2026-21241-ancillary-function-driver

    Post summary

    A write‑up details a use‑after‑free bug in AFD.sys (CVE‑2026‑21241) and provides a PoC link, noting the issue was fixed in March’s patch Tuesday.

    4320110676.6K
    275 followersView on X
  • Souhail Hammou@Dark_Puzzle
    Disclosure

    I've published the first entry in my new Windows vulnerability research series. It details how exploring Windows I/O completion internals led to uncovering a use-after-free in afd.sys (CVE-2026-21241). https://rce4fun.blogspot.com/2026/02/use-after-free-in-afdsys-cve-2026-21241.html

    Post summary

    The author announces the discovery of a use‑after‑free flaw in afd.sys (CVE‑2026‑21241) and shares a blog post detailing the findings, but does not provide proof of exploitation or remediation steps.

    1290101705.8K
    2.2K followersView on X
  • Souhail Hammou@Dark_Puzzle
    Patch

    This month's Patch Tuesday fixes CVE-2026-21241, a use-after-free I reported in the Ancillary Function Driver for WinSock (afd.sys). I am planning a blog series covering my recent findings in the Windows kernel, to be released after coordination with @msftsecresponse. https://t.co/wFb61C9ANX

    Post summary

    Patch Tuesday fixed CVE-2026-21241, a use‑after‑free in Windows’ afd.sys; the author plans a blog series after coordinating with Microsoft.

    78077205.7K
    2.3K followersView on X
  • hackyboiz@hackyboiz2
    Disclosure

    [1day-1line] CVE-2026-21241: Use-After-Free LPE Vulnerability Caused by I/O Mini-Completion Packet Lifetime Management Error in Windows afd.sys Hello, this is Libera. Today's 1day-1line is about a Use-After-Free Privilege Escalation (LPE) vulnerability occurring in afd.sys, a WinSock kernel driver for Windows. This vulnerability occurs during the socket state notification process; while AfdNotifyPostEvents briefly releases the spinlock, socket cleanup (AfdNotifyDestroyContext) releases mini-completion packets without cancellation, causing the remaining released packets in the queue to be dequeued. Please refer to the blog post for more details! https://hackyboiz.github.io/2026/06/15/Libera/CVE-2026-21241/

    Post summary

    The announcement outlines a use‑after‑free privilege escalation flaw in Windows afd.sys, detailing its cause while offering no proof‑of‑concept, exploit code, mitigation, or evidence of active exploitation.

    017063213.8K
    525 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-20700 2 - CVE-2025-1234 3 - CVE-2026-21513 4 - CVE-2026-21241 5 - CVE-2025-5959 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post lists five trending CVEs without providing additional details or context.

    00020299
    1.7K followersView on X
  • stasi@stasichief
    PoC

    @Bad_Jubies how do you manage to get old version of windows image to test the poc here https://bad-jubies.github.io/cve-2026-21241-ancillary-function-driver

    Post summary

    The tweet seeks instructions for acquiring an older Windows image to test a proof-of-concept for CVE-2026-21241 and links to a repository that likely contains the PoC details.

    10000106
    21 followersView on X
  • kawn@kawn2020
    Disclosure

    #windowsupdate #microsoft (つづき) ・CVE-2026-21238 7.8 Windows Ancillary Function Driver for WinSock ・CVE-2026-21241 7  Windows Ancillary Function Driver for WinSock ・CVE-2026-21253 7  メールスロット ファイル システム ・CVE-2026-21511 7.5 Microsoft Office Outlook

    Post summary

    The tweet lists newly disclosed Windows CVEs with severity scores, without providing PoC, exploitation details, or patch information.

    10000123
    89 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-21241 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. https://www.cve.org/CVERecord?id=CVE-2026-21241

    Post summary

    CVE-2026-21241 is a use-after-free flaw in the Windows Ancillary Function Driver for WinSock that permits an authorized local attacker to elevate privileges. The post provides technical details but no PoC, exploit code, patch, or evidence of active exploitation.

    00010138
    56.5K followersView on X
  • Doctor Kloud@doctorkloud
    Patch

    Use after free dans le driver WinSock : un attaquant local passe admin sans bruit. Élévation de privilèges locale, exploitation post-compromission. Le vrai risque : chaîner cette faille avec un accès initial banal. Patcher maintenant, pas demain. #CVE https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21241

    Post summary

    The post alerts readers to a use‑after‑free bug in the WinSock driver that can allow local privilege escalation, emphasizing the need to apply the vendor’s patch immediately.

    0000047
    13 followersView on X
  • ✪ 𝕱𝖆𝖍𝖆𝖉@fad_777
    Disclosure

    ثغرة Use-After-Free في ملف نواة ويندوز afd.sys تم توثيقها تحت المعرّف CVE-2026-21241. هذا النوع من الثغرات يُعد عالي الخطورة لأنه قد يؤدي إلى تنفيذ تعليمات برمجية بصلاحيات النظام (Kernel-Level Privileges)، مما يفتح الباب أمام تصعيد الصلاحيات والسيطرة الكاملة على النظام في حال تم استغلاله بنجاح. هذا النوع من الثغرات يبرز أهمية تحديث الأنظمة باستمرار ومتابعة مكونات النواة منخفضة المستوى التي غالبًا ما تكون هدفًا رئيسيًا للمهاجمين. A Use-After-Free vulnerability in the Windows kernel component afd.sys, tracked as CVE-2026-21241, could allow attackers to achieve kernel-level code execution and privilege escalation if successfully exploited. This class of vulnerabilities highlights why keeping operating systems patched and closely monitoring low-level kernel components is critical for maintaining a strong security posture. Source: https://rce4fun.blogspot.com/2026/02/use-after-free-in-afdsys-cve-2026-21241.html #CyberSecurity #WindowsSecurity #KernelSecurity #Vulnerability #InfoSec #Exploit #CVE

    Post summary

    The post announces a high‑severity use‑after‑free flaw in Windows afd.sys (CVE‑2026‑21241) that could enable kernel‑level code execution and privilege escalation, emphasizing the need for timely patching.

    0000082
    63 followersView on X
CPE platform detail9 entries

9 of 9 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_11_23h2--arm64
OSmicrosoftwindows_11_23h2--x64
OSmicrosoftwindows_11_24h2--arm64
OSmicrosoftwindows_11_24h2--x64
OSmicrosoftwindows_11_25h2--arm64
OSmicrosoftwindows_11_25h2--x64
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_2022_23h2---
OSmicrosoftwindows_server_2025---

Explore more