kernel exploitation
Exploiting CVE-2026-21241: A Use-After-Free Race in AFD.sys
A deep-dive into CVE-2026-21241 — a use-after-free race in afd.sys's socket notification path, where a notification object is freed across a spinlock release, reclaimed with a named-pipe spray, and pivoted through kCFG-legal RtlSetBit calls into a KDP-evading SeDebugPrivilege flip and SYSTEM.
