CVE-2026-25179Disclosure(microsoft / windows_10_1607)

LOWCVSS 7.0 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Improper validation of specified type of input in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1287

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1607
  • windows_10_1809
  • windows_10_21h2
  • windows_10_22h2

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-03-16)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
windows_10_1607windows_10_1809windows_10_21h2windows_10_22h2windows_11_23h2windows_11_24h2windows_11_25h2windows_11_26h1windows_server_2012windows_server_2016

2 versions affected across 14 products

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-10: 1Mentions · 2026-03-16: 2PoC Mentioned / Linked · 2026-03-10: 1Technical Details · 2026-03-10: 1Technical Details · 2026-03-16: 203-1003-16
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-101
Disclosure1
2026-03-162
Disclosure1General1
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-25179 Improper validation of specified type of input in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. https://www.cve.org/CVERecord?id=CVE-2026-25179 ----- Traducción: CVE-2026-25179 Validación inap… http://infoflow.cloud`

    Post summary

    A brief disclosure of CVE-2026-25179, highlighting local privilege escalation via improper input validation in Windows Ancillary Function Driver for WinSock.

    0000038
    58 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-25179 Improper validation of specified type of input in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. https://www.cve.org/CVERecord?id=CVE-2026-25179

    Post summary

    CVE-2026-25179 is a privilege‑elevation flaw in Windows Ancillary Function Driver for WinSock, but no PoC, exploit, or patch details are mentioned.

    00000251
    56.7K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    ⚠️ CVE-2026-25179: Windows Ancillary Function Driv... AFD kernel driver input validation bypass hits every Windows 10 build—local privesc with SYSTEM access guaranteed once ... https://zerodaysignal.com/vulnerability/CVE-2026-25179 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    A new Windows 10 local privilege escalation vulnerability (CVE‑2026‑25179) affecting the AFD kernel driver has been disclosed, with an input‑validation bypass described, but no active exploitation, patch, or PoC code detail is provided.

    0000043
    143 followersView on X
CPE platform detail25 entries

25 of 25 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1607--x64
OSmicrosoftwindows_10_1607--x86
OSmicrosoftwindows_10_1809--x64
OSmicrosoftwindows_10_1809--x86
OSmicrosoftwindows_10_21h2--arm64
OSmicrosoftwindows_10_21h2--x64
OSmicrosoftwindows_10_21h2--x86
OSmicrosoftwindows_10_22h2--arm64
OSmicrosoftwindows_10_22h2--x64
OSmicrosoftwindows_10_22h2--x86
OSmicrosoftwindows_11_23h2--arm64
OSmicrosoftwindows_11_23h2--x64
OSmicrosoftwindows_11_24h2--arm64
OSmicrosoftwindows_11_24h2--x64
OSmicrosoftwindows_11_25h2--arm64
OSmicrosoftwindows_11_25h2--x64
OSmicrosoftwindows_11_26h1--arm64
OSmicrosoftwindows_11_26h1--x64
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_2022_23h2---
OSmicrosoftwindows_server_2025--x64

Explore more