Windows WinSock AFD elevation of privilege (CVE-2026-68820), exploited
Microsoft's 11 August 2026 security update for CVE-2026-68820 fixes a use-after-free in the Windows Ancillary Function Driver for WinSock. A locally authenticated attacker who wins a race with a crafted application can elevate to SYSTEM. Microsoft rates it Important, CVSS 3.1 7.0 (AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H), and marks Exploitation Detected. CISA added it to the Known Exploited Vulnerabilities catalog on 11 August 2026 with the same-day Cisco ASA/FTD and Metabase KEV batch. Apply the August 2026 cumulative update for your Windows build and reboot so the kernel driver replacement takes effect. Distinct from SharePoint CVE-2026-55040 already on this desk.
- Product
- Windows Ancillary Function Driver for WinSock (Windows client and Server)
- Versions
- Supported Windows 10/11 and Windows Server builds before the August 2026 cumulative update (see MSRC)
- CVSS
- (CVSS 3.1, Microsoft)
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H - Exploited in Australia?
- unknown
- Patch to
- August 2026 cumulative update for your build (MSRC CVE-2026-68820); reboot required
Primary: Microsoft MSRC (CVE-2026-68820) · Vendor: Microsoft Security Update Guide · CVE: CVE-2026-68820, CVE-2026-55040 · CISA KEV addition notice (11 Aug 2026)
