Home ยท Wiki ยท Vulnerabilities & CVEs
type: cve ยท created: 2026-08-12 ยท updated: 2026-08-12 ยท tags: [cve, kev, zero-day, lpe, microsoft, windows, afd-sys, winsock, exploited-in-the-wild, lazarus] ยท confidence: high ยท severity: high ยท affected_sectors: [technology, government, finance, healthcare, energy, defence] ยท au_impact: true

CVE-2026-68820 โ€” Windows afd.sys WinSock Use-After-Free LPE

CVE-2026-68820 is a use-after-free vulnerability in afd.sys, the Ancillary Function Driver for WinSock in Windows, rated CVSS 7.0. It lets an attacker with code already running on a machine escalate to SYSTEM. It is the only bug Microsoft flags as under active exploitation in the August 2026 Patch Tuesday release, and Check Point Research attributes the exploitation to the Lazarus Group's Operation Dream Job campaign. CISA added it to its KEV catalogue on 2026-08-11.

Vulnerability Details

Attribute Detail
CVE CVE-2026-68820
Type Local privilege escalation (LPE); use-after-free
Product Windows Ancillary Function Driver for WinSock (afd.sys)
CVSS 7.0
Access Requires code already running on the machine (local)
Exploitation status Actively exploited in the wild (only bug flagged as such in the release)
Attribution Lazarus Group, Operation Dream Job campaign (per Check Point Research)
KEV status Added to KEV 2026-08-11 (BOD 26-04)

Context

Patched in Microsoft's August 2026 Patch Tuesday (398 CVEs, 62 Critical per ZDI). The afd.sys zero-day is also among three KEV additions under BOD 26-04, alongside Cisco ASA/FTD (CVE-2026-20349) and Metabase (CVE-2026-72898). The digest flags it as a priority for NZISM-covered Windows estates and Essential Eight patching discipline.

Related Pages

Sources: raw/digests/Cyber-Digest-2026-08-12