Sep 2021: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2021-38638 Published on September 15, 2021
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Weakness Type
Improper Privilege Management
The software does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Products Associated with CVE-2021-38638
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2021-38638 are published in these products:
Affected Versions
Microsoft Windows 10 Version 1809:- Version 10.0.0 and below 10.0.17763.2183 is affected.
- Version 10.0.0 and below 10.0.17763.2183 is affected.
- Version 10.0.0 and below 10.0.17763.2183 is affected.
- Version 10.0.0 and below 10.0.18363.1801 is affected.
- Version 10.0.0 and below 10.0.19043.1237 is affected.
- Version 10.0.0 and below 10.0.20348.230 is affected.
- Version 10.0.0 and below 10.0.19041.1237 is affected.
- Version 10.0.0 and below 10.0.19041.1237 is affected.
- Version 10.0.0 and below 10.0.19042.1237 is affected.
- Version 10.0.0 and below 10.0.19042.1237 is affected.
- Version 10.0.0 and below 10.0.10240.19060 is affected.
- Version 10.0.0 and below 10.0.14393.4651 is affected.
- Version 10.0.0 and below 10.0.14393.4651 is affected.
- Version 10.0.0 and below 10.0.14393.4651 is affected.
- Version 6.1.0 and below 6.1.7601.25712 is affected.
- Version 6.1.0 and below 6.1.7601.25712 is affected.
- Version 6.3.0 and below 6.3.9600.20120 is affected.
- Version 6.0.0 and below 6.0.6003.21218 is affected.
- Version 6.0.0 and below 6.0.6003.21218 is affected.
- Version 6.0.0 and below 6.0.6003.21218 is affected.
- Version 6.1.0 and below 6.1.7601.25712 is affected.
- Version 6.0.0 and below 6.1.7601.25712 is affected.
- Version 6.2.0 and below 6.2.9200.23462 is affected.
- Version 6.2.0 and below 6.2.9200.23462 is affected.
- Version 6.3.0 and below 6.3.9600.20120 is affected.
- Version 6.3.0 and below 6.3.9600.20120 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.