
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21241 is a use-after-free (UAF) vulnerability in the Windows Ancillary Function Driver for WinSock (afd.sys) that allows a low-privileged local attacker to elevate privileges to SYSTEM level. It affects multiple Windows versions including Windows 11 (23H2, 24H2, 25H2, 26H1), Windows Server 2022, Windows Server 2022 23H2, and Windows Server 2025. Microsoft disclosed and patched the vulnerability on February 10, 2026, as part of the February 2026 Patch Tuesday security update cycle. It carries a CVSS v3.1 base score of 7.0 (High) (Microsoft MSRC, Feedly).
The vulnerability is classified as CWE-416 (Use After Free) and resides in afd.sys, the Windows Ancillary Function Driver that underpins WinSock network operations. A use-after-free condition occurs when the driver accesses memory that has already been freed, allowing an attacker to manipulate freed memory to redirect execution flow and gain elevated privileges. Exploitation requires low privileges and no user interaction, but has high attack complexity (AC:H), meaning reliable exploitation may require specific timing or race condition conditions to be met. A public proof-of-concept exploit has been published by researcher _jle_k, with a detailed write-up and PoC code available (jle-k blog, GitHub PoC, rce4fun blog).
Successful exploitation allows a low-privileged local attacker to escalate privileges to SYSTEM, granting complete administrative control over the affected Windows system. This impacts confidentiality, integrity, and availability at a HIGH level, enabling an attacker to install malware, access all data, disable security controls, or pivot laterally within a network. Active exploitation in the wild has been reported, making this a significant risk for enterprise environments where attackers may already have limited local access (Microsoft MSRC, BleepingComputer).
afd.sys by manipulating WinSock driver objects — freeing a memory object and then accessing it to corrupt kernel memory structures. This may require timing a race condition (high attack complexity).svchost.exe or user-mode applications with elevated token privileges.%SystemRoot%\Minidump if exploitation attempts fail.CVE-2026-21241.c or compiled variants) in user-writable directories such as %TEMP%, %APPDATA%, or C:\Users\<user>\Downloads.Microsoft released patches on February 10, 2026, as part of the February 2026 Patch Tuesday update. Administrators should update affected systems to the following minimum build versions: Windows 11 23H2 → 10.0.22631.6649, Windows 11 24H2 → 10.0.26100.7781, Windows 11 25H2 → 10.0.26200.7781, Windows Server 2022 → 10.0.20348.4711, Windows Server 2022 23H2 → 10.0.25398.2149, Windows Server 2025 → 10.0.26100.32313. Given active exploitation in the wild, patching should be treated as an urgent priority, particularly for internet-facing or multi-user systems. No official workaround short of patching has been published by Microsoft (Microsoft MSRC, Qualys Blog).
The vulnerability was highlighted by BleepingComputer as one of six actively exploited zero-days in the February 2026 Patch Tuesday, drawing significant community attention (BleepingComputer). Security researcher _jle_k published a detailed exploitation blog post and shared findings on social media (xcancel.com), while researcher yarden_shafir also commented on the vulnerability (jle-k blog). Sophos, Rapid7, Qualys, and SOCRadar all covered the vulnerability in their February 2026 Patch Tuesday reviews, with Rapid7 and Qualys emphasizing the active exploitation risk (Rapid7 Blog, Qualys Blog). The SANS Internet Storm Center also noted the vulnerability in its diary entry for the patch cycle (SANS ISC).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."