CVE-2025-32709
Microsoft · Published May 13, 2025
7.8
CVSS v3.1
HIGHCISA KEV — Federal agencies must patch by deadline
Actively exploited in the wild
Patch availableGet patch
Description
Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
Affected Products
- Windows 10 1507 < 10.0.10240.21014
- Windows 10 1607 < 10.0.14393.8066
- Windows 10 1809 < 10.0.17763.7314
- Windows 10 21h2 < 10.0.19044.5854
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H