CVE-2025-32709 is a local privilege escalation vulnerability in the Windows Ancillary Function Driver for WinSock affecting all major Windows versions. While the affected products include Windows Server editions that can be internet-facing, this vulnerability requires local access and authorized user privileges to exploit, making it unsuitable for direct internet exploitation via T1190.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: OTHER
CVE Published: 2025-05-13
Added to CISA KEV: 2025-05-13 0 DAY BETWEEN CVE AND KEV
CVE-2025-32709 is a security vulnerability in the Windows Ancillary Function Driver for WinSock (`AFD.sys`), a core component of the Windows networking subsystem [2]. It was disclosed and addressed as part of Microsoft’s May 2025 security updates [3].
Description. Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. Metrics.
On April 10, 2025, a new local privilege escalation vulnerability was uncovered in Microsoft Windows' core network subsystem, specifically in the Ancillary Function Driver for WinSock (AFD.sys). Tracked as CVE-2025-32709, this vulnerability centers around a *use-after-free* (UAF) condition. Unlike r…
CVE-2025-32709 - Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability. CVE-2025-32709 is an 'Use-After-Free ...
CVE-2025-32709 is a use after free vulnerability in Windows Ancillary Function Driver for WinSock that allows local privilege escalation. NVD provides CVSS scores, CWE ID, affected software configurations, and vendor advisories for this vulnerability.
Attackers have been actively exploiting CVE-2025-32709, a critical use-after-free vulnerability in Microsoft's Windows Ancillary Function Driver for WinSock ( ...
High severity Unreviewed Published on May 13, 2025 to the GitHub Advisory Database • Updated on Oct 21, 2025 ... Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.