{"cveID":"CVE-2025-32709","vendorProject":"Microsoft","product":"Windows","vulnerabilityName":"Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability","dateAdded":"2025-05-13","shortDescription":"Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to escalate privileges to administrator.","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","dueDate":"2025-06-03","knownRansomwareCampaignUse":"Unknown","notes":"https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2025-32709 ; https://nvd.nist.gov/vuln/detail/CVE-2025-32709","cwes":["CWE-416"],"year":2025,"state":"mapped","stale_reasons":[],"mappings":[{"domain":"enterprise","cve":"CVE-2025-32709","technique":"T1068","technique_name_at_mapping":"Exploitation for Privilege Escalation","mapping_type":"exploitation_technique","capability_group":"use_after_free","comments":"This use-after-free vulnerability in Windows has been exploited by attackers to gain SYSTEM-level privileges, leading to remote code execution, full system compromise, the modification of system processes to establish persistence on the machine, and the deployment of malware such as credential harvesters and ransomware.","references":["https://www.darkreading.com/vulnerabilities-threats/windows-zero-day-bug-exploited-browser-rce"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2025-32709","technique":"T1003","technique_name_at_mapping":"OS Credential Dumping","mapping_type":"primary_impact","capability_group":"use_after_free","comments":"This use-after-free vulnerability in Windows has been exploited by attackers to gain SYSTEM-level privileges, leading to remote code execution, full system compromise, the modification of system processes to establish persistence on the machine, and the deployment of malware such as credential harvesters and ransomware.","references":["https://www.darkreading.com/vulnerabilities-threats/windows-zero-day-bug-exploited-browser-rce"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2025-32709","technique":"T1059","technique_name_at_mapping":"Command and Scripting Interpreter","mapping_type":"primary_impact","capability_group":"use_after_free","comments":"This use-after-free vulnerability in Windows has been exploited by attackers to gain SYSTEM-level privileges, leading to remote code execution, full system compromise, the modification of system processes to establish persistence on the machine, and the deployment of malware such as credential harvesters and ransomware.","references":["https://www.darkreading.com/vulnerabilities-threats/windows-zero-day-bug-exploited-browser-rce"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2025-32709","technique":"T1543","technique_name_at_mapping":"Create or Modify System Process","mapping_type":"primary_impact","capability_group":"use_after_free","comments":"This use-after-free vulnerability in Windows has been exploited by attackers to gain SYSTEM-level privileges, leading to remote code execution, full system compromise, the modification of system processes to establish persistence on the machine, and the deployment of malware such as credential harvesters and ransomware.","references":["https://www.darkreading.com/vulnerabilities-threats/windows-zero-day-bug-exploited-browser-rce"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2025-32709","technique":"T1608.001","technique_name_at_mapping":"Upload Malware","mapping_type":"primary_impact","capability_group":"use_after_free","comments":"This use-after-free vulnerability in Windows has been exploited by attackers to gain SYSTEM-level privileges, leading to remote code execution, full system compromise, the modification of system processes to establish persistence on the machine, and the deployment of malware such as credential harvesters and ransomware.","references":["https://www.darkreading.com/vulnerabilities-threats/windows-zero-day-bug-exploited-browser-rce"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"}],"techniques":[{"id":"T1003","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"OS Credential Dumping","name_at_mapping":"OS Credential Dumping","renamed":false,"revoked_by":null,"mapping_types":["primary_impact"],"sigma_rule_count":37,"has_detection_strategy":true},{"id":"T1059","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Command and Scripting Interpreter","name_at_mapping":"Command and Scripting Interpreter","renamed":false,"revoked_by":null,"mapping_types":["primary_impact"],"sigma_rule_count":95,"has_detection_strategy":true},{"id":"T1068","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Exploitation for Privilege Escalation","name_at_mapping":"Exploitation for Privilege Escalation","renamed":false,"revoked_by":null,"mapping_types":["exploitation_technique"],"sigma_rule_count":31,"has_detection_strategy":true},{"id":"T1543","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Create or Modify System Process","name_at_mapping":"Create or Modify System Process","renamed":false,"revoked_by":null,"mapping_types":["primary_impact"],"sigma_rule_count":9,"has_detection_strategy":true},{"id":"T1608.001","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Upload Malware","name_at_mapping":"Upload Malware","renamed":false,"revoked_by":null,"mapping_types":["primary_impact"],"sigma_rule_count":0,"has_detection_strategy":true}],"mapping_types":["exploitation_technique","primary_impact"],"has_exploitation_technique":true,"mapping_attack_versions":["16.1"],"mapping_domains":["enterprise"],"sigma_coverage":"partial","sigma_rules_tagged_cve":[],"added_after_mapping_snapshot":false,"_source":"kevmap","_built":"2026-08-24 19:45 UTC","_attack_version":"19.2"}