You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
afd.sys use after free
About this tag
The tag afd.sys use after free covers discussions about a high-severity local privilege escalation vulnerability in the Windows Ancillary Function Driver for WinSock (AFD.sys). Tracked as CVE-2026-32073, this use-after-free flaw received a CVSS 3.1 score of 7.0 and was published by Microsoft on April 14, 2026. The vulnerability allows a low-privileged local attacker to elevate privileges to system level, making it a critical security concern for Windows administrators. Topics include patch management, exploitation risks, and mitigation strategies for this specific driver flaw.
Microsoft’s CVE-2026-32073 is the kind of Windows security advisory that makes defenders stop and re-evaluate their patch queue: it is a local elevation-of-privilege flaw in the Windows Ancillary Function Driver for WinSock, better known as AFD.sys, and it is already being tracked as a...