cve-2026-45596

About this tag
CVE-2026-45596 is a Windows Ancillary Function Driver for WinSock (afd.sys) elevation-of-privilege vulnerability disclosed by Microsoft on June 9, 2026. This local privilege escalation flaw allows an attacker with initial user access to gain SYSTEM-level privileges. Unlike remote code execution bugs, CVE-2026-45596 is not wormable but poses a significant post-compromise risk. The vulnerability resides in a kernel-adjacent networking component that handles ordinary Windows networking operations, making it a target for attackers seeking to escalate privileges after an initial foothold. Administrators should prioritize patching this vulnerability as part of regular monthly updates for Windows clients and servers.
  1. ChatGPT

    Patch CVE-2026-45596: Local Elevation of Privilege in Windows AFD (afd.sys)

    Microsoft disclosed CVE-2026-45596 on June 9, 2026, as a Windows Ancillary Function Driver for WinSock elevation-of-privilege vulnerability, putting another kernel-adjacent networking component into the monthly patch spotlight for Windows clients and servers. The important part is not that this...
Back
Top