CVE-2026-24293
vulnerability analysis and mitigation

Overview

CVE-2026-24293 is a null pointer dereference vulnerability in the Windows Ancillary Function Driver (AFD) for WinSock that allows a locally authenticated, low-privileged attacker to elevate privileges on affected systems. It was disclosed and patched on March 10, 2026, as part of Microsoft's March 2026 Patch Tuesday security update cycle. Affected products include Windows 10 (21H2, 22H2), Windows 11 (23H2, 24H2, 25H2, 26H1), Windows Server 2022, Windows Server 2022 23H2, and Windows Server 2025. The vulnerability carries a CVSS v3.1 base score of 7.8 (High) (Microsoft MSRC).

Technical details

The root cause is a null pointer dereference (CWE-476) in the Windows Ancillary Function Driver (afd.sys) for WinSock, a kernel-mode driver that provides socket-related functionality to user-mode applications. An authorized local attacker with low privileges can trigger the dereference through a crafted system call or socket operation, causing the kernel to access a null memory address. Because the vulnerable code path runs in kernel context, successful exploitation can lead to privilege escalation. No public proof-of-concept code or detailed technical write-up has been identified at this time (Microsoft MSRC).

Impact

Successful exploitation grants an attacker complete control over the affected Windows system, with high impact to confidentiality, integrity, and availability. A low-privileged local user could escalate to SYSTEM-level privileges, enabling them to read or exfiltrate sensitive data, modify system configurations and files, install malware or backdoors, and potentially disrupt system availability. The broad scope of affected products — spanning consumer and enterprise Windows versions — increases the potential attack surface, particularly in multi-user or shared environments where lateral movement post-escalation is a concern (Microsoft MSRC).

Mitigation and workarounds

Microsoft released patches on March 10, 2026, as part of the March 2026 Patch Tuesday update. Organizations should update to the following minimum versions: Windows 10 21H2 (10.0.19044.7058), Windows 10 22H2 (10.0.19045.7058), Windows 11 23H2 (10.0.22631.6783), Windows 11 24H2 (10.0.26100.7979), Windows 11 25H2 (10.0.26200.7979), Windows 11 26H1 (10.0.28000.1719), Windows Server 2022 (10.0.20348.4830), Windows Server 2022 23H2 (10.0.25398.2207), and Windows Server 2025 (10.0.26100.32463). As a compensating control, organizations should enforce the principle of least privilege to limit the number of low-privileged accounts that could exploit this vulnerability, and monitor for suspicious privilege escalation activity (Microsoft MSRC).

Community reactions

The vulnerability was covered as part of broader March 2026 Patch Tuesday roundups by multiple security outlets. Rapid7, Sophos, Zero Day Initiative (ZDI), and SANS ISC all published patch Tuesday reviews that included this CVE among the 79+ vulnerabilities addressed that month. Coverage was routine and did not single out this vulnerability as particularly notable compared to the zero-days patched in the same cycle (Rapid7 Blog, Sophos Blog, ZDI Blog, SANS ISC).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management