Junglewise Threat Intelligence

CVE-2026-68820: Microsoft Windows Ancillary Function Driver for WinSock use-after-free

CVE-2026-68820 · Severity: critical · CVSS 7 · Exploited in the wild · Published 2026-08-11

Executive brief

A security vulnerability exists in a core Windows networking component responsible for handling socket connections. An attacker who already has limited access to a computer could exploit this flaw to gain full administrative control over the system. This vulnerability is reportedly being used in active attacks, making immediate patching essential to prevent unauthorized system takeovers.

Technical details

A use-after-free (UAF) vulnerability exists in the Windows Ancillary Function Driver (afd.sys) for WinSock. The flaw is triggered when the driver improperly handles objects in memory, allowing a local attacker with low privileges to execute code in kernel mode. While the attack complexity is rated as high, successful exploitation results in a complete loss of confidentiality, integrity, and availability (elevation to SYSTEM). This vulnerability is confirmed to be exploited in the wild and is addressed in Microsoft's August 2026 security updates.

Affected products

  • Microsoft Windows 10 Version 1607 10.0.14393.0 to 10.0.14393.9418
  • Microsoft Windows 10 Version 1809 10.0.17763.0 to 10.0.17763.9115
  • Microsoft Windows 10 Version 21H2 10.0.19044.0 to 10.0.19044.7663
  • Microsoft Windows 10 Version 22H2 10.0.19045.0 to 10.0.19045.7663
  • Microsoft Windows 11 Version 23H2 10.0.22631.0 to 10.0.22631.7517
  • Microsoft Windows 11 Version 24H2 10.0.26100.0 to 10.0.26100.9168
  • Microsoft Windows 11 Version 25H2 10.0.26200.0 to 10.0.26200.9168
  • Microsoft Windows 11 Version 26H1 10.0.28000.0 to 10.0.28000.2704

Timeline

  • 2026-08-11: disclosed
  • 2026-08-11: patched
  • 2026-08-11: kev added: Added to CISA KEV catalog due to active exploitation.

Related threats