Cyber Posture

CVE-2026-21238

HighLPE

Published: 10 February 2026

Published
10 February 2026
Modified
11 February 2026
KEV Added
Patch
CVSS Score 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0003 10.6th percentile
Risk Priority 16 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2026-21238 is a high-severity Improper Access Control (CWE-284) vulnerability in Microsoft Windows 10 21H2. Its CVSS base score is 7.8 (High).

Operationally, exploitation aligns with the MITRE ATT&CK technique Exploitation for Privilege Escalation (T1068); ranked at the 10.6th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

The strongest mitigations our analysis identified are NIST 800-53 AC-25 (Reference Monitor) and AC-3 (Access Enforcement).

Threat & Defense at a Glance

What attackers do: exploitation maps to Exploitation for Privilege Escalation (T1068). What defenders deploy: see the NIST 800-53 controls recommended below.
Threat & Defense Details

Mitigating Controls (NIST 800-53 r5)AI

prevent

Enforces approved authorizations for logical access to system resources, directly preventing unauthorized privilege escalation due to improper access control in the Windows Ancillary Function Driver for WinSock.

prevent

Implements a tamper-proof reference monitor to mediate all subject-object accesses, addressing the kernel driver's failure to properly enforce access control policies.

prevent

Employs least privilege to restrict low-privilege local attackers from gaining high-impact access even if the driver's improper controls are exploited.

MITRE ATT&CK Enterprise TechniquesAI

T1068 Exploitation for Privilege Escalation Privilege Escalation
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges.
Why these techniques?

Local improper access control vulnerability in a Windows kernel driver directly enables exploitation for privilege escalation from low-privileged context to full system compromise.

Confidence: HIGH · MITRE ATT&CK Enterprise v18.1

NVD Description

Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Deeper analysisAI

CVE-2026-21238 is an improper access control vulnerability (CWE-284) in the Windows Ancillary Function Driver for WinSock. Published on 2026-02-10T18:16:24.613, it carries a CVSS v3.1 base score of 7.8 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) and affects Windows systems where the driver is present.

The vulnerability enables a local attacker with low privileges to exploit improper access controls in the driver, resulting in privilege escalation. Successful exploitation grants the attacker high-impact access to confidentiality, integrity, and availability, potentially allowing full system compromise from an initial low-privilege position.

Mitigation details are available in the official advisory from the Microsoft Security Response Center at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21238.

Details

CWE(s)

Affected Products

microsoft
windows 10 1607
≤ 10.0.14393.8868 · ≤ 10.0.14393.8868
microsoft
windows 10 1809
≤ 10.0.17763.8389 · ≤ 10.0.17763.8389
microsoft
windows 10 21h2
≤ 10.0.19044.6937 · ≤ 10.0.19044.6937 · ≤ 10.0.19044.6937
microsoft
windows 10 22h2
≤ 10.0.19045.6937 · ≤ 10.0.19045.6937 · ≤ 10.0.19045.6937
microsoft
windows 11 23h2
≤ 10.0.22631.6649 · ≤ 10.0.22631.6649
microsoft
windows 11 24h2
≤ 10.0.26100.7781 · ≤ 10.0.26100.7781
microsoft
windows 11 25h2
≤ 10.0.26200.7781 · ≤ 10.0.26200.7781
microsoft
windows server 2012
all versions, r2
microsoft
windows server 2016
≤ 10.0.14393.8868
microsoft
windows server 2019
≤ 10.0.17763.8389
+3 more product configuration(s) — see NVD for full list

CVEs Like This One

CVE-2026-27914Same product: Microsoft Windows 10 1607
CVE-2026-20843Same product: Microsoft Windows 10 1607
CVE-2026-25176Same product: Microsoft Windows 10 1607
CVE-2025-59230Same product: Microsoft Windows 10 1607
CVE-2025-21293Same product: Microsoft Windows 10 1607
CVE-2025-21359Same product: Microsoft Windows 10 1607
CVE-2026-20929Same product: Microsoft Windows 10 1607
CVE-2026-24290Same product: Microsoft Windows 10 1809
CVE-2026-21255Same product: Microsoft Windows 10 1607
CVE-2026-20809Same product: Microsoft Windows 10 1607

References