CVE-2026-68820: Microsoft Windows Driver Zero-Day Under Attack
- Severity
- HIGH
- Affected component
- microsoft windows ancillary function driver (other)
- Patched version
- Not yet available
A confirmed high-severity vulnerability, CVE-2026-68820, affects the Microsoft Windows Ancillary Function Driver for WinSock. This flaw allows local privilege escalation and is being exploited in the wild by the Lazarus group.
What happened
The Microsoft Windows Ancillary Function Driver for WinSock has been found to contain a use-after-free vulnerability, tracked as CVE-2026-68820. This vulnerability allows an authorized attacker to elevate privileges locally by triggering a race condition in the driver. Microsoft has confirmed that this flaw is being actively exploited by the Lazarus group in their Operation Dream Job campaign, targeting defense-sector companies.
The vulnerability was first flagged on August 11, 2026, and confirmed the next day. Microsoft released patches as part of their August 2026 Patch Tuesday updates. However, no authoritative version range for affected systems has been published yet. Users are advised to monitor for patches and apply them as soon as they become available.
What to do about it
- Monitor official Microsoft security updates for patches related to CVE-2026-68820.
- Apply any available patches immediately upon release to mitigate the risk of exploitation.
- Review system logs for any signs of unauthorized activity that may indicate exploitation of this vulnerability.
- Consider implementing additional security measures to detect and respond to potential attacks targeting this vulnerability.
- No official fix has been published yet for specific version ranges. Monitor the sources below for updates.
How 0Day would have caught this
microsoft windows ancillary function driver is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
If you are using Microsoft Windows, you may be affected. However, no authoritative version range has been published yet. Monitor official sources for updates.
What should I do right now?
Monitor for patches and apply them as soon as they are available. Review system logs for any signs of unauthorized activity.
Has this been exploited in the wild?
Yes, this vulnerability is being actively exploited by the Lazarus group in their Operation Dream Job campaign.