CVE detail
CVE-2025-21418
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 23.0 · diversity 18.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
9 source links · newest first
- Week in review: Microsoft fixes two actively exploited 0-days, PAN-OS auth bypass hole pluggedHelp Net Security
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Microsoft fixes two actively exploited zero-days (CVE-2025-21418, CVE-2025-21391) February 2025 Patch Tuesday is here, and Microsoft has delivered fixes for 56 vulnerabilities, including two zero-days – CVE-2025-21418 and CVE-2025-21391 – under active exploitation. PAN-OS authentication bypass hole plugged, PoC is public (CVE-2025-0108) Palo Alto Networks has fixed a high-severity authentication bypass vulnerability (CVE-2025-0108) in the management web interface of its … More →
newswww.helpnetsecurity.comFeb 16, 2025, 9:00 AM ClearSky Cyber Security says it has seen a new Windows zero-day being exploited by a Chinese APT named Mustang Panda.
newswww.securityweek.comFeb 14, 2025, 11:40 AM- U.S. CISA adds Microsoft Windows, Zyxel device flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Windows, Zyxel device flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: The vulnerability CVE-2024-40891 is a command injection issue in Zyxel CPE Series devices that remains unpatched and has not yet […]
newssecurityaffairs.comFeb 12, 2025, 8:01 AM - Microsoft Patch Tuesday security updates for February 2025 ficed 2 actively exploited bugsSecurity Affairs
Microsoft Patch Tuesday security updates for February 2025 addressed four zero-day flaws, two of which are actively exploited in the wild. Microsoft Patch Tuesday security updates for February 2025 addressed 57 vulnerabilities in Windows and Windows Components, Office and Office Components, Azure, Visual Studio, and Remote Desktop Services. Two of these vulnerabilities are listed as […]
newssecurityaffairs.comFeb 12, 2025, 7:27 AM February 2025 Patch Tuesday is here, and Microsoft has delivered fixes for 56 vulnerabilities, including two zero-days – CVE-2025-21418 and CVE-2025-21391 – under active exploitation. CVE-2025-21418 and CVE-2025-21391 CVE-2025-21418 is a vulnerability in the Windows Ancillary Function Driver (AFD.sys), which interfaces with the Windows Sockets API to enable Windows applications to connect to the internet. It can be exploited by attackers to elevate privileges on the target host. “An authenticated user would need to run … More →
newswww.helpnetsecurity.comFeb 11, 2025, 8:15 PMThe Microsoft Patch Tuesday machine hummed loudly this month with urgent fixes for a pair of already-exploited Windows zero-days.
newswww.securityweek.comFeb 11, 2025, 7:59 PMNo excerpt available.
Mitigationwww.cisa.govFeb 11, 2025, 6:15 PM- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21418msrc.microsoft.com
No excerpt available.
Vendor Advisorymsrc.microsoft.comFeb 11, 2025, 6:15 PM February 2025 Patch Tuesday is now live: Microsoft fixes two actively exploited zero-days (CVE-2025-21418, CVE-2025-21391) The new year has started with a whirlwind of activity, and one of the hottest topics in the news is the increasing emphasis on AI. DeepSeek ad Stargate DeepSeek took the world by storm as millions of copies were downloaded to personal devices, but soon security concerns arose as to how the chatbot used personal data. As research continues, many … More →
newswww.helpnetsecurity.comFeb 10, 2025, 6:00 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2025-59295CVSS 8.8 · High
Heap-based buffer overflow in Internet Explorer allows an unauthorized attacker to execute code over a network.
- CVE-2025-59275CVSS 7.8 · High
Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.
- CVE-2025-59242CVSS 7.8 · High
Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
- CVE-2025-58725CVSS 7.0 · High
Heap-based buffer overflow in Windows COM allows an authorized attacker to elevate privileges locally.
- CVE-2025-54894CVSS 7.8 · High
Local Security Authority Subsystem Service Elevation of Privilege Vulnerability
- CVE-2025-53766CVSS 9.8 · Critical
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.