🚨SEVERITY: HIGH — CVSS 7.0Security Advisory

TL;DR 📌

  • Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.
  • Highest CVSS: 7.0 (High).
  • Listed in CISA KEV (2026-08-11) — this is being exploited in the wild.
  • Check the advisory for fixed releases — remediation detail is in the vendor link below.
  • CVEs: CVE-2026-68820.

What it is

CVE-2026-68820 is a use-after-free vulnerability in the Ancillary Function Driver for WinSock (AFD.sys), the kernel-mode driver that underpins Windows socket operations. It sits on the local attack surface, not the network data plane: exploitation requires local access and low-privilege authentication on the target host.