Skip to main content

CVE detail

CVE-2026-68820

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVSS 7.0 · HighBuzz score 75.0KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 75.0

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 30.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
30.0
22 evidence mentions in the snapshot
Diversity score
20.0
19 sources across 4 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
22
within the 30d window
Peak daily
13
highest bucket

Evidence

Source links by recency

Newest mentions first
22 source links · newest first
  • North Korean hackers have been exploiting a Windows zero-day vulnerability (CVE-2026-68820) to target defense-sector companies as part of the Operation Dream Job campaign. [...]

    newswww.bleepingcomputer.comAug 12, 2026, 3:38 PM
  • Lazarus Used Post-Quantum Key Exchange to Deliver Zero-DayInfosecurity Magazine

    ch reported the vulnerability to Microsoft on July 28 and published its analysis on August 11, the day a patch shipped. CVE-2026-68820 is a use-after-free race condition in AFD.sys, the driver handling network sockets in the Windows kernel, and was the only flaw in this the August Patch Tuesday release Microsoft flagged as under active exploitation. Th

    newswww.infosecurity-magazine.comAug 12, 2026, 1:35 PM
  • y downloader that profiles the compromised system and retrieves additional components. One of those components exploits CVE-2026-68820, a local privilege escalation vulnerability in the Windows AFD.sys driver. Successful exploitation gives the attackers SYSTEM privileges and lets them deploy FudModule, a Lazarus kernel-mode rootkit built to interfere w

    newswww.helpnetsecurity.comAug 12, 2026, 11:48 AM
  • h Tuesday delivered security fixes for 400+ vulnerabilities, including one that has been exploited in zero-day attacks (CVE-2026-68820) and three that were publicly disclosed prior to the release of the patches. Vulnerabilities of note CVE-2026-68820 is a use-after-free flaw that affects the Windows Ancillary Function Driver for WinSock (AFD.sys) and a

    newswww.helpnetsecurity.comAug 12, 2026, 9:34 AM
  • ForestTiger , a known Lazarus backdoor. Advertisement. Scroll to continue reading. The afd.sys zero-day, now tracked as CVE-2026-68820, is a use-after-free issue that allows attackers to trigger a race condition and gain System privileges. On August 11, Microsoft fixed the vulnerability as part of its Patch Tuesday updates , and the US cybersecurity ag

    newswww.securityweek.comAug 12, 2026, 8:45 AM
  • Microsoft Fixes 400 Flaws on August Patch TuesdayInfosecurity Magazine

    hallenge to process for organizations without automated, risk-based patching programs. The actively exploited zero day (CVE-2026-68820) is a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock. A locally authenticated attacker with low privileges could run a specially crafted application and trigger a race condition to gai

    newswww.infosecurity-magazine.comAug 12, 2026, 8:12 AM
  • affected by August 2026 Patch Tuesday Exploited Zero-Day Vulnerability in Windows Ancillary Function Driver for WinSock CVE-2026-68820 is an Important elevation of privilege vulnerability affecting the Windows Ancillary Function Driver for WinSock and has a CVSS score of 7.0 . A use-after-free flaw (CWE-416) allows a low-privileged local attacker to el

    vendorwww.crowdstrike.comAug 12, 2026, 8:00 AM
  • Microsoft Patch Tuesday for August 2026 fixes 398 CVEs, including an actively exploited zero-day and a wormable DNS flaw enabling remote code execution. Microsoft released its Patch Tuesday security updates for August 2026 on Tuesday, covering 398 new CVEs across Windows, Office, Azure, Exchange Server, SharePoint, Teams, GitHub Copilot, .NET, and a range of other […]

    newssecurityaffairs.comAug 12, 2026, 6:49 AM
  • ued today in Microsoft’s August Patch Tuesday releases. The hole is in Windows’ Ancillary Function Driver for WinSock ( CVE-2026-68820 ), which, according to Todd Schell , principal product manager at Ivanti, has been a recurring target for local privilege-escalation bugs throughout 2026. Past vulnerabilities in this component have let an authorized at

    newswww.csoonline.comAug 12, 2026, 12:45 AM
  • arked as "critical." Microsoft notes that 1 of the vulnerabilities disclosed this month have been exploited in the wild CVE-2026-68820 is an elevation of privilege vulnerability affecting Windows Ancillary Function Driver for WinSock. A Use After Free vulnerability could allow an authorized attacker to elevate privileges locally. This vulnerability has

    vendorblog.talosintelligence.comAug 11, 2026, 10:21 PM
  • ation denial-of-service, and arbitrary code execution. Zero-day Vulnerabilities Patched in August Patch Tuesday Edition CVE-2026-72971: Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering Vulnerability This is a link-following flaw that may allow an authenticated attacker to perform local tampering. CVE-2026-62832: Windows User Profile

    vendorblog.qualys.comAug 11, 2026, 9:55 PM
  • (and possibly other miscreants) found and attacked one of these flaws as a zero-day in early June. The bug, tracked as CVE-2026-68820, is a use-after-free in the Windows Ancillary Function Driver for WinSock. “A locally authenticated attacker could run a specially crafted application on an affected system to trigger a race condition,” Redmond warned,

    newswww.theregister.comAug 11, 2026, 9:31 PM
  • Microsoft Plugs Nearly 400 Security HolesKrebs on Security

    Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today.

    newskrebsonsecurity.comAug 11, 2026, 9:28 PM
  • ktop browser security patches so far this month. SharePoint: critical RCE chain by Rapid7 Today sees the publication of CVE-2026-63520 , a high-severity remote code execution in Microsoft SharePoint. Discovered by Rapid7 Senior Principal Security Researcher Stephen Fewer , and published today in coordination with Microsoft; this vulnerability is the se

    vendorwww.rapid7.comAug 11, 2026, 9:10 PM
  • h code already running on a machine can use it to escalate to SYSTEM. That patch goes out first. The flaw is tracked as CVE-2026-68820 (CVSS score: 7.0) and is the only

    newsthehackernews.comAug 11, 2026, 8:10 PM
  • cluding a high-severity vulnerability that has been exploited in the wild as a zero-day. The exploited flaw, tracked as CVE-2026-68820, is described as a use-after-free issue in Ancillary Function Driver for WinSock (afd.sys), the kernel-mode driver functioning as the backbone for the Windows Sockets API. Microsoft says threat actors have been exploiti

    newswww.securityweek.comAug 11, 2026, 6:46 PM
  • of the vulnerabilities patched this month, followed by remote code execution (RCE) vulnerabilities at 27.1%. Important CVE-2026-68820 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability CVE-2026-68820 is an EoP vulnerability affecting Windows Ancillary Function Driver for WinSock. It received a CVSSv3 score of 7.0 and

    vendorwww.tenable.comAug 11, 2026, 6:04 PM
  • The August 2026 Security Update ReviewZero Day Initiative

    g actively exploited, at least as 0-days. Again, we’ll start with the bug under active attack and move on from there. - CVE-2026-68820 - Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability This bug allows attackers to execute code at SYSTEM level. Bugs of this type are often paired with code execution bugs to take over a

    vendorwww.thezdi.comAug 11, 2026, 5:56 PM
  • YSTEM** privileges and disable EDR visibility. Following responsible disclosure, Microsoft assigned the vulnerability **CVE-2026-68820** and released a patch on August 11, 2026, as part of their August Patch Tuesday updates. The attackers’ command-and-control infrastructure consists of compromised **Roundcube** and **WordPress** servers hosting **Relay

    newsresearch.checkpoint.comAug 11, 2026, 5:30 PM
  • No excerpt available.

    Mitigationwww.cisa.govAug 11, 2026, 5:19 PM
  • Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

    vendormsrc.microsoft.comAug 11, 2026, 2:00 PM
  • ee new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-20349 Cisco Secure Firewall Adaptive Security Appliance (ASA) and Firewall Threat Defense (FTD) Heap Inspection Vulnerability CVE-2026-68820 Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability

    governmentwww.cisa.govAug 11, 2026, 12:00 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence