CVE descriptions are notoriously vague. A few lines of text, a CVSS score, and you're left asking: what does this actually mean, and how does it work? Translating that into a working understanding of the underlying flaw requires a structured methodology and a willingness to dig into the internals of the target system. This talk walks through the full research lifecycle of CVE-2026-21236 - a heap-based buffer overflow in the Windows Ancillary Function Driver for WinSock (AFD.sys) - from a blank slate to the first publicly available analysis report. We’ll cover each phase of the process, including lessons that are learned along the way. Attendees will come away with a workflow and practical tips for turning a Windows CVE into real understanding.