🚨SEVERITY: HIGH — CVSS 7.0Security Advisory
TL;DR 📌
- Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.
- Highest CVSS: 7.0 (High).
- Listed in CISA KEV (2026-08-11) — this is being exploited in the wild.
- Check the advisory for fixed releases — remediation detail is in the vendor link below.
- CVEs: CVE-2026-68820.
What it is
CVE-2026-68820 is a use-after-free vulnerability in the Ancillary Function Driver for WinSock (AFD.sys), the kernel-mode driver that underpins Windows socket operations. It sits on the local attack surface, not the network data plane: exploitation requires local access and low-privilege authentication on the target host.