Affected Systems
Windows kernel driver afd.sys (Ancillary Function Driver for WinSock) across all supported Windows versions. CVE-2026-68820 is a use-after-free vulnerability enabling local privilege escalation to SYSTEM level. CVSS 7.0.
Exploitation Status
Actively exploited in the wild. Check Point Research attributes exploitation to Lazarus APT group in Operation Dream Job campaign. Exploitation requires triggering a race condition in the network socket operations driver.
Business Impact
Attackers with initial code execution on Windows systems can escalate to SYSTEM privileges, gaining full control of the host. This is a post-compromise escalation vector used by a sophisticated APT group. Microsoft flags this as the only actively exploited flaw in the August 2026 Patch Tuesday release. Organizations with existing endpoint compromise or those targeted by Lazarus should treat this as highest priority despite the moderate CVSS score.
Urgency
🔴 Immediate
Recommended Actions
- Deploy Microsoft August 2026 Patch Tuesday updates immediately to all Windows endpoints and servers, prioritizing CVE-2026-68820
- Hunt for indicators of Lazarus Operation Dream Job activity, including suspicious job-themed phishing and LinkedIn recruitment lures
- Review Windows Security Event Logs (Event ID 4672, 4673, 4688) for unexpected SYSTEM-level privilege escalations and anomalous process creation
- Audit systems for signs of prior compromise where attackers may have already gained initial access and could leverage this zero-day
- Apply defense-in-depth controls: restrict local admin rights, enable credential guard, and deploy EDR with behavioral detection for privilege escalation attempts
