CVE-2026-68820 โ Windows afd.sys WinSock Use-After-Free LPE
CVE-2026-68820 is a use-after-free vulnerability in afd.sys, the Ancillary Function Driver for WinSock in Windows, rated CVSS 7.0. It lets an attacker with code already running on a machine escalate to SYSTEM. It is the only bug Microsoft flags as under active exploitation in the August 2026 Patch Tuesday release, and Check Point Research attributes the exploitation to the Lazarus Group's Operation Dream Job campaign. CISA added it to its KEV catalogue on 2026-08-11.
Vulnerability Details
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-68820 |
| Type | Local privilege escalation (LPE); use-after-free |
| Product | Windows Ancillary Function Driver for WinSock (afd.sys) |
| CVSS | 7.0 |
| Access | Requires code already running on the machine (local) |
| Exploitation status | Actively exploited in the wild (only bug flagged as such in the release) |
| Attribution | Lazarus Group, Operation Dream Job campaign (per Check Point Research) |
| KEV status | Added to KEV 2026-08-11 (BOD 26-04) |
Context
Patched in Microsoft's August 2026 Patch Tuesday (398 CVEs, 62 Critical per ZDI). The afd.sys zero-day is also among three KEV additions under BOD 26-04, alongside Cisco ASA/FTD (CVE-2026-20349) and Metabase (CVE-2026-72898). The digest flags it as a priority for NZISM-covered Windows estates and Essential Eight patching discipline.
Related Pages
- Microsoft Patches 398 Flaws Including A Windows Driver Zero Day Under Active Att โ the August 2026 Patch Tuesday release
- Cisa Adds Three Known Exploited Vulnerabilities To Catalog โ CISA KEV addition incident
Sources: raw/digests/Cyber-Digest-2026-08-12