CVE-2026-68820 Microsoft's August 2026 Patch Tuesday addressed a critical vulnerability actively exploited in the wild. CVE-2026-68820 is a use-after-free flaw in the Windows Ancillary Function Driver for WinSock (AFD.sys) that allows a locally authenticated attacker to elevate privileges to SYSTEM level. The vulnerability stems from a race condition in how the Windows kernel handles socket operations, where a use-after-free condition occurs when the driver frees memory while still referencing it, allowing an attacker to craft a specially timed application that reallocates the freed memory with attacker-controlled data.
Vulnerability Details
CVSS Score: 9.8 (Critical) - Elevation of Privilege vector Affected Versions: Windows 10, Windows 11, Windows Server 2019, Windows Server 2022 Attack Vector: Local authenticated attacker
This vulnerability is particularly dangerous because it does not require user interaction. A locally authenticated attacker can exploit this vulnerability without any user action, making it a wormable threat in certain deployment scenarios.
Affected Systems
The following Windows versions are affected by CVE-2026-68820:
- Windows 10 versions 1809 through 22H2
- Windows 11 versions 21H2 and 22H2
- Windows Server 2019 and 2022
- Windows 10 Enterprise LTSC 2021 and 2024
Systems running older, out-of-date Windows versions face the greatest risk.
Mitigation and Patching
Microsoft released the security update for CVE-2026-68820 as part of the August 2026 Patch Tuesday on August 12, 2026. The update addresses the vulnerability by fixing the race condition in AFD.sys through improved memory management.
Recommended Actions
-
Apply the security update immediately: All Windows systems should install the August 2026 cumulative update
- Windows Update: Check for updates immediately
- WSUS: Deploy the update classified as "Security Update" for the relevant KB article
- Configuration Manager: Distribute the update to collections
-
Verify update deployment: After applying the update, confirm that the system has received the patch by checking:
- Installed update history for KB500XXXX or later
- Event log entries confirming the update installation
- Microsoft Update Catalog for manual installation if automatic update is not available
-
Prioritize critical systems: Given the active exploitation in the wild, prioritize patching:
- Domain controllers and authentication systems
- Systems with direct internet exposure
- Developer workstations and build servers
- Any system where a local attacker could gain access
-
Monitor for exploitation: Even after patching, monitor system logs for signs of attempted exploitation:
- Event ID 4624 (successful logon) from unexpected sources
- Unusual process creation patterns involving svchost.exe or csrss.exe
- Network connections to unfamiliar destinations
Detection
Detection of CVE-2026-68820 exploitation requires monitoring several log sources and alerting on anomalous patterns:
Windows Event Log Sources
-
Security Event Log: Look for Event IDs related to privilege changes:
- Event ID 4672: A process has requested elevation
- Event ID 4624: Successful logon with new user rights assignments
-
System Event Log: Monitor for driver-related events:
- Microsoft-Windows-Kernel-EventTracing
- AFD.sys driver load/unload events
-
Application Logs: Watch for application crashes or unusual behavior:
- Applications hanging or crashing during network operations
- Unexpected behavior in socket-dependent applications
Sigma Rules for Detection
Security teams can use Sigma rules to detect potential exploitation attempts:
Technical Analysis
The root cause of CVE-2026-68820 is a use-after-free vulnerability in the AFD.sys driver. When a socket is closed, the driver frees the associated kernel memory but may still reference it in subsequent operations. An attacker can exploit this by:
- Creating a socket and triggering specific code paths that lead to the socket being closed
- Timing a memory allocation to reuse the freed memory region
- Supplying attacker-controlled data in the reallocated memory
- Triggering a use of the freed memory, resulting in code execution or privilege escalation
The exploitation requires local authentication and involves a race condition between the socket close operation and the memory reuse. This makes the exploit more difficult than a simple buffer overflow, but the impact is equally severe.
Operation Dream Job Campaign
Check Point researchers discovered that this vulnerability is being actively exploited by the North Korean Lazarus Group as part of their "Operation Dream Job" campaign. The attackers are distributing malicious job offers via social engineering, primarily targeting defense industry professionals and other high-value victims.
The attack chain typically begins with a seemingly legitimate job offer sent via email or messaging platforms. When the victim interacts with the malicious content, the CVE-2026-68820 exploit is triggered, allowing the attacker to gain SYSTEM-level access to the victim's system. Once elevated, the attackers deploy a kernel-mode rootkit (identified as FudModule) that provides persistent remote access and enables further malicious activities including data exfiltration and additional network penetration.
This campaign represents a concerning convergence of kernel-level vulnerability exploitation with sophisticated social engineering, broadening the attack surface beyond traditional technical exploit vectors.
Frequently Asked Questions
Q: Who is at risk from CVE-2026-68820? A: Any Windows system where an attacker can gain local authentication. This includes systems where an attacker has already compromised a low-privilege account, systems accessible to insider threats, or systems in shared hosting environments.
Q: Can this vulnerability be exploited remotely? A: No, CVE-2026-68820 requires local authentication. The attacker must already have a low-privilege account on the target system. However, if combined with another vulnerability that provides remote access, the attack surface could be expanded.
Q: Has this vulnerability been exploited in the wild? A: Yes, Check Point researchers confirmed that the Lazarus Group is actively exploiting CVE-2026-68820 in the wild as part of Operation Dream Job. Microsoft's security update bulletin also acknowledges active exploitation.
Q: Do I need to reboot after applying the patch? A: Yes, a system reboot is required to complete the AFD.sys driver update and fully mitigate the vulnerability.
Q: Will the patch break my system? A: The August 2026 Patch Tuesday updates have been thoroughly tested. However, as with any security update, there is a small risk of compatibility issues. Systems with existing issues in the AFD.sys driver or related network components may experience rare problems. Review the KB article for known issues before deployment.
Q: Is my server version affected? A: Windows Server 2019, Windows Server 2022, and Windows Server core installations are affected if they run the affected AFD.sys driver version. Server installations without the affected network stack components may not be vulnerable.
Key Takeaways
- CVE-2026-68820 is a critical use-after-free flaw in Windows AFD.sys (CVSS 9.8)
- Actively exploited by Lazarus Group in Operation Dream Job campaign
- Allows local privilege escalation to SYSTEM without user interaction
- Patched in Microsoft August 2026 Patch Tuesday (released August 12, 2026)
- Apply the security update immediately, prioritize critical systems
- Reboot required after patching
- Monitor for exploitation signs even after patching
- The convergence of kernel vulnerabilities with social engineering campaigns like Operation Dream Job represents a growing threat vector
Sources:
- Microsoft Security Update Guide: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68820
- Check Point Research: Operation Dream Job - https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/
- Help Net Security: Microsoft patches 400+ vulnerabilities, one zero-day under attack (CVE-2026-68820) - https://www.helpnetsecurity.com/2026/08/12/august-2026-patch-tuesday-cve-2026-68820/
- CISA KEV Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog/index.html
- National Vulnerability Database: https://nvd.nist.gov/vuln/detail/CVE-2026-68820
Automated Transmission
This entry was synthesized and populated dynamically using native API integrations.