Use After Free Vulnerability in Windows Ancillary Function Driver by Microsoft
CVE-2026-33099
7HIGH
Key Information:
- Vendor
Microsoft
- Vendor
- CVE Published:
- 14 April 2026
What is CVE-2026-33099?
A use after free vulnerability in the Windows Ancillary Function Driver for WinSock could allow an attacker who has already gained access to the system to elevate their privileges. This occurs due to improper handling of memory, which may potentially be exploited by an authorized user to gain unauthorized access to critical system areas or perform malicious actions. It is crucial for users to ensure their systems are updated with the latest security patches to mitigate this risk.
Affected Version(s)
Windows 10 Version 1607 32-bit Systems 10.0.14393.0 < 10.0.14393.9060
Windows 10 Version 1809 32-bit Systems 10.0.17763.0 < 10.0.17763.8644
Windows 10 Version 21H2 32-bit Systems 10.0.19044.0 < 10.0.19044.7184