CVE-2026-68820 is a high-severity privilege escalation flaw in Windows AFD.sys actively exploited in the wild. Patch affected Windows systems immediately.
| Product | Version Start | Version End (excl.) | Status |
|---|---|---|---|
| windows_10_1607 | * | 10.0.14393.9418 | vulnerable |
| windows_10_1607 | * | 10.0.14393.9418 | vulnerable |
| windows_10_1809 | * | 10.0.17763.9115 | vulnerable |
| windows_10_1809 | * | 10.0.17763.9115 | vulnerable |
| windows_10_21h2 | * | 10.0.19044.7663 | vulnerable |
| windows_10_22h2 | * | 10.0.19045.7663 | vulnerable |
| windows_11_23h2 | * | 10.0.22631.7517 | vulnerable |
| windows_11_24h2 | * | 10.0.26100.9106 | vulnerable |
| windows_11_25h2 | * | 10.0.26200.9106 | vulnerable |
| windows_11_26h1 | * | 10.0.28000.2704 | vulnerable |
| windows_server_2012 | - | - | vulnerable |
| windows_server_2012 | r2 | r2 | vulnerable |
| windows_server_2016 | * | 10.0.14393.9418 | vulnerable |
| windows_server_2019 | * | 10.0.17763.9115 | vulnerable |
| windows_server_2022 | * | 10.0.20348.5440 | vulnerable |
| windows_server_2025 | * | 10.0.26100.33222 | vulnerable |
Immediately install the latest security updates provided by Microsoft for the Windows Ancillary Function Driver (AFD.sys) via Windows Update, WSUS, or Microsoft Endpoint Configuration Manager.
Ensure all Windows 10, 11, and Windows Server instances are updated to versions exceeding the vulnerable thresholds, such as build 10.0.19045.7663 for Windows 10 22H2 or 10.0.26100.9106 for Windows 11 24H2.
Enforce the principle of least privilege (PoLP) to limit local access. Since the attack vector is local, reducing the number of users with interactive login rights and implementing application whitelisting can mitigate the risk of exploit execution.
Follow CISA’s BOD 26-04 guidance for forensic triage. Monitor for unusual kernel-mode driver activity, unexpected SYSTEM process creation from low-privilege accounts, and system crashes (BSOD) that may indicate exploit attempts.
"Detection should focus on identifying local privilege escalation attempts. Monitor Windows Event Logs for Event ID 4688 (Process Creation) involving suspicious tools or unexpected SYSTEM-level processes spawned from low-privilege accounts. Use EDR solutions to flag unusual memory access patterns or API calls targeting afd.sys. Additionally, watch for system instability or 'Blue Screen of Death' (BSOD) events that may indicate failed exploitation attempts of this use-after-free vulnerability."
Experience superior visibility and a simpler approach to cyber risk management