Fixing and finding
Jump to remediation plan
CVE ID

CVE-2026-68820

Published 2026-08-11
Updated 27 days ago
Vendor/s
Microsoft
Product/s
Windows Ancillary Function Driver for WinSock
Version/s
* > 10.0.14393.9418
KEV Status
Active Exploitation
Listed in CISA's Known Exploited Vulnerabilities catalog. Active exploitation observed in the wild.
CVSS Score (v3.1)
7
/ 10
High
Severity Details
Base score
7 High
Attack vector
Local
Attack complexity
High
Privileges required
Low
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Description

CVE-2026-68820 is a high-severity privilege escalation flaw in Windows AFD.sys actively exploited in the wild. Patch affected Windows systems immediately.

CPE

Microsoft logo
Microsoft
Product Version Start Version End (excl.) Status
windows_10_1607 * 10.0.14393.9418 vulnerable
windows_10_1607 * 10.0.14393.9418 vulnerable
windows_10_1809 * 10.0.17763.9115 vulnerable
windows_10_1809 * 10.0.17763.9115 vulnerable
windows_10_21h2 * 10.0.19044.7663 vulnerable
windows_10_22h2 * 10.0.19045.7663 vulnerable
windows_11_23h2 * 10.0.22631.7517 vulnerable
windows_11_24h2 * 10.0.26100.9106 vulnerable
windows_11_25h2 * 10.0.26200.9106 vulnerable
windows_11_26h1 * 10.0.28000.2704 vulnerable
windows_server_2012 - - vulnerable
windows_server_2012 r2 r2 vulnerable
windows_server_2016 * 10.0.14393.9418 vulnerable
windows_server_2019 * 10.0.17763.9115 vulnerable
windows_server_2022 * 10.0.20348.5440 vulnerable
windows_server_2025 * 10.0.26100.33222 vulnerable

Related weakness (CWE)

CWE-416

Remediation plan

1

Apply official patches

Immediately install the latest security updates provided by Microsoft for the Windows Ancillary Function Driver (AFD.sys) via Windows Update, WSUS, or Microsoft Endpoint Configuration Manager.

2

Update affected systems

Ensure all Windows 10, 11, and Windows Server instances are updated to versions exceeding the vulnerable thresholds, such as build 10.0.19045.7663 for Windows 10 22H2 or 10.0.26100.9106 for Windows 11 24H2.

3

Restrict access

Enforce the principle of least privilege (PoLP) to limit local access. Since the attack vector is local, reducing the number of users with interactive login rights and implementing application whitelisting can mitigate the risk of exploit execution.

4

Monitor for exploitation

Follow CISA’s BOD 26-04 guidance for forensic triage. Monitor for unusual kernel-mode driver activity, unexpected SYSTEM process creation from low-privilege accounts, and system crashes (BSOD) that may indicate exploit attempts.

Detection Guidance

"Detection should focus on identifying local privilege escalation attempts. Monitor Windows Event Logs for Event ID 4688 (Process Creation) involving suspicious tools or unexpected SYSTEM-level processes spawned from low-privilege accounts. Use EDR solutions to flag unusual memory access patterns or API calls targeting afd.sys. Additionally, watch for system instability or 'Blue Screen of Death' (BSOD) events that may indicate failed exploitation attempts of this use-after-free vulnerability."

References

Sources

NIST National Vulnerability Database (NVD)
CISA Known Exploited Vulnerabilities (KEV)

Experience superior visibility and a simpler approach to cyber risk management