Windows Ancillary Function Driver for WinSock zero-day privilege escalation (CVE-2026-68820)
Vulnerability
Summary
Hide ▲
Show ▼
CVE-2026-68820 in Windows Ancillary Function Driver for WinSock (AFD.sys) was patched after active exploitation in zero-day attacks, leaving affected Windows systems exposed to SYSTEM privilege escalation. Microsoft said a locally authenticated attacker could run a specially crafted application to trigger a race condition and elevate privileges. The flaw was used in intrusions to deploy FudModule, making it a high-risk local escalation issue for Windows administrators.
Related Happenings
CCB urgent patch warning for CVE-2026-41089 on Windows servers
Public Sector Action
H score48
First: 01.06.2026 15:30
Last: 01.06.2026 15:30
Sources 1
About this happening:
Belgium's CCB warned that CVE-2026-41089 is being actively exploited in the wild, urging admins to immediately patch vulnerable Windows servers because the fla...
CCB urgent patch warning for CVE-2026-41089 on Windows servers
Public Sector ActionAbout this happening: Belgium's CCB warned that CVE-2026-41089 is being actively exploited in the wild, urging admins to immediately patch vulnerable Windows servers because the fla...
Windows RPC PhantomRPC local privilege escalation flaw
Vulnerability
H score19
First: 28.04.2026 14:31
Last: 28.04.2026 14:31
Sources 1
About this happening:
PhantomRPC in Windows RPC can let a local attacker elevate to System across all Windows versions, creating a high-impact privilege-escalation path. The flaw abuses...
Windows RPC PhantomRPC local privilege escalation flaw
VulnerabilityAbout this happening: PhantomRPC in Windows RPC can let a local attacker elevate to System across all Windows versions, creating a high-impact privilege-escalation path. The flaw abuses...
CISA orders FCEB remediation for CVE-2025-60710
Public Sector Action
H score34
First: 15.04.2026 17:51
Last: 15.04.2026 17:51
Sources 1
About this happening:
CISA added CVE-2025-60710 to its actively exploited catalog and gave FCEB agencies two weeks to secure systems under BOD 22-01. The move targets a Windows Ta...
CISA orders FCEB remediation for CVE-2025-60710
Public Sector ActionAbout this happening: CISA added CVE-2025-60710 to its actively exploited catalog and gave FCEB agencies two weeks to secure systems under BOD 22-01. The move targets a Windows Ta...
Silver Fox South Asia phishing campaign
Campaign
H score34
First: 24.03.2026 18:00
Last: 24.03.2026 18:00
Sources 1
About this happening:
The Silver Fox campaign now includes BYOVD abuse of a previously unknown WatchDog Anti-malware driver, amsdk.sys (version 1.0.600), to disable security tools on co...
Silver Fox South Asia phishing campaign
CampaignAbout this happening: The Silver Fox campaign now includes BYOVD abuse of a previously unknown WatchDog Anti-malware driver, amsdk.sys (version 1.0.600), to disable security tools on co...
Microsoft Secure Boot certificate expiration guidance for Windows devices
Advisory/Mitigation
H score48
First: 14.01.2026 11:38
Last: 14.01.2026 11:38
Sources 1
About this happening:
Microsoft warned that Secure Boot certificates used by most Windows devices expire starting in June 2026, creating a risk that some personal and business systems may n...
Microsoft Secure Boot certificate expiration guidance for Windows devices
Advisory/MitigationAbout this happening: Microsoft warned that Secure Boot certificates used by most Windows devices expire starting in June 2026, creating a risk that some personal and business systems may n...
Latest development: 10.02.2026 21:06
Microsoft released Windows 10 KB5075912 and continues rolling out replacement Secure Boot certificates to targeted Windows devices through monthly Windows updates, expanding delivery only after devices show sufficient successful update signals ahead of the June 2026 expiration.
Timeline
-
11.08.2026 21:08 2 articles · 2h ago
Microsoft patches Windows AFD.sys zero-day CVE-2026-68820 after Lazarus exploitation
Mitigation Patch UpdateMicrosoft’s August 2026 Patch Tuesday fixed CVE-2026-68820 in the Windows Ancillary Function Driver for WinSock (AFD.sys), a use-after-free flaw that lets a locally authenticated attacker elevate privileges to SYSTEM. Check Point said Lazarus exploited the zero-day in intrusions to deploy a new version of FudModule, making the issue a patched local privilege-escalation risk for affected Windows systems.
Show sources
- Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days — www.bleepingcomputer.com — 11.08.2026 21:08
- Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days — www.bleepingcomputer.com — 11.08.2026 21:08