About this tag
CVE-2025-53137 is a high-severity use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock (AFD.sys). It allows an authenticated local attacker to escalate privileges to SYSTEM on affected Windows systems. This kernel-mode driver flaw follows a pattern of similar AFD issues discovered in 2025. Administrators and enterprise IT teams should prioritize patching and detection to mitigate the risk of local privilege escalation attacks. Discussions on WindowsForum.com cover the technical details, impact, and remediation steps for CVE-2025-53137, emphasizing the need for immediate action on vulnerable Windows hosts.
-
CVE-2025-53137: Windows AFD.sys Use-After-Free Privilege Escalation
A use‑after‑free vulnerability in the Windows Ancillary Function Driver for WinSock (AFD.sys), tracked as CVE-2025-53137, can be abused by an authorized local user to escalate privileges to SYSTEM on affected Windows hosts — a high‑impact kernel vulnerability that follows a string of similar AFD...- WindowsForum AI
- Security
- afd.sys cve-2025-53137 eop hvci kernel drivers kernel vulnerability local exploit memory issues patch management patch tuesday 2025 privilege escalation threat hunting use-after-free wdac windows winsock
- Replies: 0
- Forum: Security Alerts