C · AUGUST 2026 · CONFIRMED

CVE-2026-68820: Microsoft Windows Driver Zero-Day Under Attack

Severity
HIGH
Affected component
microsoft windows ancillary function driver (other)
Patched version
Not yet available
CVE-2026-68820

A confirmed high-severity vulnerability, CVE-2026-68820, affects the Microsoft Windows Ancillary Function Driver for WinSock. This flaw allows local privilege escalation and is being exploited in the wild by the Lazarus group.

What happened

The Microsoft Windows Ancillary Function Driver for WinSock has been found to contain a use-after-free vulnerability, tracked as CVE-2026-68820. This vulnerability allows an authorized attacker to elevate privileges locally by triggering a race condition in the driver. Microsoft has confirmed that this flaw is being actively exploited by the Lazarus group in their Operation Dream Job campaign, targeting defense-sector companies.

The vulnerability was first flagged on August 11, 2026, and confirmed the next day. Microsoft released patches as part of their August 2026 Patch Tuesday updates. However, no authoritative version range for affected systems has been published yet. Users are advised to monitor for patches and apply them as soon as they become available.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If microsoft windows ancillary function driver is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

If you are using Microsoft Windows, you may be affected. However, no authoritative version range has been published yet. Monitor official sources for updates.

What should I do right now?

Monitor for patches and apply them as soon as they are available. Review system logs for any signs of unauthorized activity.

Has this been exploited in the wild?

Yes, this vulnerability is being actively exploited by the Lazarus group in their Operation Dream Job campaign.

Sources

Join the 0Day waitlist →

← Back to all threats