
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21238 is a local privilege escalation vulnerability in the Windows Ancillary Function Driver (AFD) for WinSock, caused by improper access control (CWE-284). An authenticated attacker with low privileges can exploit this flaw to elevate to SYSTEM-level privileges on affected Windows systems. It was disclosed and patched on February 10, 2026, as part of Microsoft's February 2026 Patch Tuesday. Affected products span a wide range of Windows versions including Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2), Windows Server 2012/2012 R2, 2016, 2019, 2022, and 2025. The vulnerability carries a CVSS v3.1 base score of 7.8 (High) (Microsoft MSRC).
The root cause is improper access control (CWE-284) within the Windows Ancillary Function Driver (afd.sys) for WinSock, a kernel-mode driver that provides support for Windows Sockets API operations. The attack vector is local, requiring an attacker to already have authenticated access to the system with low privileges and no user interaction. By exploiting the access control flaw in the AFD driver, an attacker can trigger a code path that grants elevated kernel-level privileges, ultimately achieving SYSTEM access. No public proof-of-concept or detailed technical write-up has been identified at this time (Microsoft MSRC).
Successful exploitation allows an authenticated local attacker to escalate from a low-privileged user account to SYSTEM-level privileges, resulting in complete system compromise. This grants the attacker the ability to read and modify sensitive data, install malware or rootkits, create unauthorized accounts, disable security controls, and potentially facilitate lateral movement within a network. The broad scope of affected Windows versions — spanning consumer and enterprise editions from Windows 10 1607 through Windows Server 2025 — significantly widens the potential attack surface (Microsoft MSRC).
Microsoft released patches for all affected Windows versions on February 10, 2026, as part of Patch Tuesday. Administrators should apply the relevant cumulative updates immediately: Windows 11 24H2/25H2 (build 10.0.26100.7781 or later), Windows 11 23H2 (10.0.22631.6649 or later), Windows 10 21H2/22H2 (10.0.19044.6937 / 10.0.19045.6937 or later), Windows 10 1809/Server 2019 (10.0.17763.8389 or later), Windows 10 1607/Server 2016 (10.0.14393.8868 or later), Windows Server 2022 (10.0.20348.4711 or later), Windows Server 2022 23H2 (10.0.25398.2149 or later), and Windows Server 2025 (10.0.26100.32313 or later). As interim mitigations, restrict local system access to trusted users only, apply the principle of least privilege, and deploy endpoint detection and response (EDR) solutions to monitor for suspicious privilege escalation activity (Microsoft MSRC).
CVE-2026-21238 was covered as part of broader February 2026 Patch Tuesday roundups by multiple security vendors and researchers. Qualys, Rapid7, Sophos, and BleepingComputer all included it in their Patch Tuesday analyses, noting it as one of 58 vulnerabilities addressed that month alongside 6 actively exploited zero-days. The vulnerability itself did not receive outsized individual attention, as it lacks a public exploit and was not among the zero-days flagged as actively exploited (BleepingComputer, Qualys Blog, Sophos Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."