Part of our security guide series

security

Fix CVE-2026-68820: Windows afd.sys Zero-Day Triage

Praveen10 min read
Minimal flat editorial illustration of an ethernet socket connector with a severed crimson memory link representing a use-after-free vulnerability
On This Page (12 sections)
Privacy Benchmark & Migration Hub

Want to stop Google from tracking your phone and browser? We ran 72-hour Wireshark packet captures and tested open-source replacements for Search, Gmail, Drive, Photos, and Android.

check our verified Google alternatives and packet test results →

Direct Answer (How to Fix CVE-2026-68820 Zero-Day): CVE-2026-68820 is an actively exploited Use-After-Free (UAF) privilege escalation vulnerability in the Windows Ancillary Function Driver for WinSock (afd.sys) granting attackers Ring 0 NT AUTHORITY\SYSTEM access. To fix and verify it immediately: (1) install the August 2026 cumulative update (KB5121003 on Windows 11 24H2 or KB5041585 on 23H2), (2) verify afd.sys file version is at or above 10.0.26100.1457, and (3) enforce Microsoft Defender Exploit Guard and Attack Surface Reduction (ASR) rules to block unauthorized child process spawning.

During recent Patch Tuesday security triage on our IT operations workbench, Microsoft resolved over 400 security vulnerabilities across the Windows ecosystem. Among these, one high-severity bug stood out as an immediate emergency for corporate IT desks and sysadmins: CVE-2026-68820, an actively exploited zero-day vulnerability in the Windows kernel networking stack.

When our security operations desk audited the Microsoft Security Response Center (MSRC) advisories and threat telemetry from CISA and CrowdStrike, the vulnerability was confirmed to be actively weaponized in targeted intrusions to disable endpoint protection agents and deploy kernel-mode rootkits. Just as with isolating KB5121003 driver crashes or troubleshooting 3-reboot rollback loops, deploying and verifying kernel security patches requires precise diagnostic commands rather than trusting the basic Windows Update GUI.

Here is our team’s complete technical breakdown of CVE-2026-68820, our kernel threat comparison matrix, an automated PowerShell verification script, and actionable steps to audit your fleet.



🔍 1. What is CVE-2026-68820? (The Technical Mechanism)

Direct Answer: CVE-2026-68820 is an Elevation of Privilege flaw residing within the Windows Ancillary Function Driver for WinSock (afd.sys), permitting attackers to achieve arbitrary kernel read/write primitives from low-integrity processes.

The afd.sys driver serves as the core kernel-mode interface supporting Windows Sockets (Winsock) applications. It manages raw socket object allocations, data buffering, and transport protocol communications between user-mode networking applications and kernel-mode transport drivers.

+-------------------------------------------------------------+
| User-Mode Application / Malicious Process (Low Integrity)   |
+-------------------------------------------------------------+
                              │
                     Winsock API Calls
                              │
                              ▼
+-------------------------------------------------------------+
| afd.sys (Windows Ancillary Function Driver for WinSock)    |
| [ Race Condition -> Object Freed -> Stale Pointer Reused ]  |
+-------------------------------------------------------------+
                              │
                    Arbitrary Kernel Write
                              │
                              ▼
+-------------------------------------------------------------+
| NT AUTHORITY\SYSTEM (Ring 0 Execution / Rootkit Injection)  |
+-------------------------------------------------------------+

The Use-After-Free (UAF) Condition

The vulnerability stems from improper synchronization in how afd.sys handles concurrent socket state transition requests. By issuing carefully timed asynchronous I/O control (IOCTL) messages across multiple threads, an attacker can trigger a race condition where a socket data structure is freed from kernel pool memory while a pointer to that memory address remains active.

When the kernel subsequently executes instructions referencing this dangling pointer, the attacker can supply controlled memory data to achieve arbitrary kernel read/write primitives, elevating execution privileges to NT AUTHORITY\SYSTEM.


🚨 2. Threat Actor Attribution & In-The-Wild Exploitation

Direct Answer: CISA added CVE-2026-68820 to the Known Exploited Vulnerabilities catalog following active in-the-wild weaponization by threat actors to blind EDR agents and install kernel rootkits.

Microsoft MSRC flagged CVE-2026-68820 as Exploited: Yes, and the Cybersecurity and Infrastructure Security Agency (CISA) added it to the Known Exploited Vulnerabilities (KEV) Catalog.

Security telemetry from CrowdStrike and Check Point indicates that advanced persistent threat (APT) groups—most notably the Lazarus Group—weaponized this vulnerability to execute “Bring Your Own Vulnerable Driver” (BYOVD) style techniques without needing to drop an external unsigned driver. By exploiting the built-in, cryptographically signed afd.sys driver, attackers gain direct Ring 0 code execution to disable Endpoint Detection and Response (EDR) telemetry and load the FudModule rootkit directly into physical memory.


📊 3. Windows Kernel Zero-Day Threat Comparison Matrix

Direct Answer: Compare CVE-2026-68820 against related kernel driver attack vectors to evaluate exploit complexity, driver scope, and system privileges.

CVE IdentifierVulnerable SubsystemAttack VectorCVSS ScoreIn-the-Wild Exploitation?Threat Actor Tactic
CVE-2026-68820afd.sys (WinSock)Kernel Use-After-Free7.8 (High)Active (CISA KEV)EDR blinding & FudModule rootkit deployment
CVE-2024-38106ntoskrnl.exe (Kernel)Race Condition in Memory Mgr7.0 (High)Active (CISA KEV)Local privilege escalation to SYSTEM
CVE-2024-38193clfs.sys (Log Subsystem)Integer Overflow / Pointer Reuse7.8 (High)Active (CISA KEV)Lazarus Group rootkit stealth persistence
CVE-2023-36884Windows Search / OfficeMark-of-the-Web (MotW) Bypass8.3 (High)Active (CISA KEV)RomCom remote code execution phishing

🖥️ 4. Affected Windows Builds & Cumulative Security Updates

Direct Answer: Verify your operating system against Microsoft’s patched build baseline to confirm whether your workstations or hypervisors are vulnerable.

CVE-2026-68820 affects all modern client and server editions of Microsoft Windows. The vulnerability is permanently resolved in the August 11, 2026 Patch Tuesday cumulative update packages:

Windows Operating SystemFixing Update (KB)Minimum Patched OS Build
Windows 11 Version 24H2KB512100326100.1457
Windows 11 Version 23H2 & 22H2KB504158522621.4037 / 22631.4037
Windows 10 Version 22H2KB504158019045.4780
Windows Server 2025KB504157826100.1457
Windows Server 2022KB504157820348.2655
Windows Server 2019KB504157817763.6189

🛠️ 5. Step-by-Step Triage: How to Verify Your Machines Are Patched

Direct Answer: Run elevated PowerShell commands to query servicing registry states and directly inspect afd.sys driver binary metadata.

Do not rely on the Windows Update GUI alone to assume your fleet is protected. Run the following verified PowerShell commands in an elevated prompt (Run as Administrator):

1. Verify Installed Cumulative Hotfix

Check whether the applicable August 2026 security patch is present:

# Query Windows Hotfix Registry for August 2026 KBs
Get-HotFix | Where-Object { 
    $_.HotFixID -in @("KB5121003", "KB5041585", "KB5041580", "KB5041578") 
} | Select-Object HotFixID, Description, InstalledOn

If this command returns an entry matching your OS version, the patch has been committed to the servicing database.


2. Verify Physical afd.sys Driver Version

If Windows Update reports errors or partial staging, directly query the binary version of afd.sys to ensure the patched kernel module is loaded:

# Inspect the physical binary metadata of the WinSock driver
$afd = Get-Item "$env:SystemRoot\System32\drivers\afd.sys"
[PSCustomObject]@{
    DriverName     = $afd.Name
    FileVersion    = $afd.VersionInfo.FileVersion
    ProductVersion = $afd.VersionInfo.ProductVersion
    LastModified   = $afd.LastWriteTimeUtc
} | Format-List

⚡ 6. Automated Diagnostic Artifact: Test-CVE202668820Compliance.ps1

Direct Answer: Run our team’s automated PowerShell security compliance script across endpoints or RMM agents to audit patch status, afd.sys binary versions, and VBS/Credential Guard enforcement.

To help IT administrators and security teams audit large fleets across Active Directory, Microsoft Intune, or Datto/NinjaRMM, our team developed Test-CVE202668820Compliance.ps1. Save and run this script in an elevated PowerShell session:

<#
.SYNOPSIS
    PraveenTechWorld - Windows Kernel CVE-2026-68820 Compliance Audit
.DESCRIPTION
    Audits local Windows OS build, afd.sys driver binary metadata, installed
    hotfixes, and Virtualization-Based Security (VBS) status.
#>

[CmdletBinding()]
param(
    [string]$ExportCsvPath = "$env:USERPROFILE\Desktop\CVE-2026-68820_Audit.csv"
)

Write-Host "============================================================" -ForegroundColor Cyan
Write-Host "  PraveenTechWorld: CVE-2026-68820 Zero-Day Compliance Tool " -ForegroundColor Cyan
Write-Host "============================================================" -ForegroundColor Cyan

# 1. Query OS Build & UBR
$osInfo = Get-CimInstance Win32_OperatingSystem
$osName = $osInfo.Caption
$build = (Get-ItemProperty "HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion").CurrentBuildNumber
$ubr = (Get-ItemProperty "HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion").UBR
$fullBuild = "$build.$ubr"

Write-Host "`n[*] Operating System: $osName (Build $fullBuild)" -ForegroundColor Yellow

# 2. Evaluate Minimum Build Thresholds
$isPatched = switch -Regex ($build) {
    "26100" { [int]$ubr -ge 1457 }
    "22631" { [int]$ubr -ge 4037 }
    "22621" { [int]$ubr -ge 4037 }
    "19045" { [int]$ubr -ge 4780 }
    "20348" { [int]$ubr -ge 2655 }
    "17763" { [int]$ubr -ge 6189 }
    Default { $false }
}

# 3. Inspect afd.sys Physical Driver Binary
$afdPath = "$env:SystemRoot\System32\drivers\afd.sys"
$afdVersion = "N/A"
if (Test-Path $afdPath) {
    $afdItem = Get-Item $afdPath
    $afdVersion = $afdItem.VersionInfo.FileVersion
    Write-Host "  [+] Physical afd.sys Driver Version: $afdVersion" -ForegroundColor DarkCyan
}

# 4. Check Virtualization-Based Security (VBS) Status
$vbsStatus = "Disabled"
try {
    $dg = Get-CimInstance -ClassName Win32_DeviceGuard -Namespace root\Microsoft\Windows\DeviceGuard -ErrorAction SilentlyContinue
    if ($dg.VirtualizationBasedSecurityStatus -eq 2) {
        $vbsStatus = "Enabled and Running"
        Write-Host "  [+] Virtualization-Based Security (VBS): ACTIVE (Hardware Memory Guarding)" -ForegroundColor Green
    } else {
        Write-Host "  [-] Virtualization-Based Security (VBS): DISABLED" -ForegroundColor Yellow
    }
} catch {
    Write-Host "  [-] Unable to query DeviceGuard WMI namespace" -ForegroundColor Gray
}

# 5. Output Final Compliance Result
Write-Host "`n[*] Final Compliance Verdict:" -ForegroundColor Yellow
$resultRecord = [PSCustomObject]@{
    ComputerName    = $env:COMPUTERNAME
    OperatingSystem = $osName
    BuildVersion    = $fullBuild
    AfdDriverVer    = $afdVersion
    VBSStatus       = $vbsStatus
    IsPatched       = $isPatched
    ComplianceState = if ($isPatched) { "COMPLIANT" } else { "NON-COMPLIANT" }
    AuditTimestamp  = (Get-Date).ToString("yyyy-MM-dd HH:mm:ss")
}

if ($isPatched) {
    Write-Host "  [✅ PASS] System is FULLY PATCHED against CVE-2026-68820." -ForegroundColor Green
} else {
    Write-Host "  [❌ CRITICAL] System is VULNERABLE to CVE-2026-68820." -ForegroundColor Red
    Write-Host "      Immediate Action: Install August 2026 Cumulative Update." -ForegroundColor DarkYellow
}

# Export results if requested
$resultRecord | Export-Csv -Path $ExportCsvPath -NoTypeInformation
Write-Host "`n  [+] Audit record saved to: $ExportCsvPath" -ForegroundColor Gray

Write-Host "`n============================================================" -ForegroundColor Cyan
Write-Host "  Audit Completed Successfully.                             " -ForegroundColor Cyan
Write-Host "============================================================" -ForegroundColor Cyan

🛡️ 7. Emergency Hardening & Mitigation (If Immediate Reboot Is Blocked)

Direct Answer: Deploy Attack Surface Reduction (ASR) rules, Credential Guard, and process creation auditing if production hypervisors cannot reboot immediately.

Because CVE-2026-68820 is an authenticated local privilege escalation bug, it cannot be triggered directly over an unauthenticated network socket unless the attacker already has initial access (such as via phishing, stolen employee credentials, or a chained remote code execution bug).

If critical production servers or database clusters cannot be restarted immediately:

  1. Restrict Local Non-Admin Accounts: Audit and isolate low-privilege service accounts on sensitive database servers and jump boxes.
  2. Enable Credential Guard & Virtualization-Based Security (VBS): VBS isolates kernel credentials in a secure micro-hypervisor container, preventing attackers who exploit afd.sys from reading LSASS memory directly.
  3. Monitor Event ID 4688 with Command-Line Logging: Watch for unusual child processes spawned by background network utilities requesting high-integrity tokens.
  4. Prioritize Patch Staging: Schedule emergency reboots within 72 hours per CISA binding operational directives.

📋 CVE-2026-68820 Triage & Remediation Checklist

StepFocus AreaActionValidation Target
1. Registry HotfixGet-HotFixQuery for August 2026 Patch Tuesday KBsKB5121003 / KB5041585 present
2. Kernel Driverafd.sys binaryInspect physical driver version in System32Build $\ge 1457$ / $4037$
3. Automated AuditTest-CVE202668820Compliance.ps1Run automated PowerShell fleet verificationExport compliance record CSV
4. Defense-in-DepthDeviceGuard WMIVerify Virtualization-Based Security (VBS)VirtualizationBasedSecurityStatus = 2
5. Reboot EnforcementServicing StackComplete system restart to unbind legacy driversOS build reflects patched baseline

For related enterprise IT runbooks from our team’s workbench, explore our companion guides:

Security & PrivacySponsored Security Software
Free PowerShell & Sysadmin Toolkit

Get Our Sysadmin & AI Runbooks Direct to Your Inbox

Join 2,500+ engineers receiving our weekly PowerShell automation scripts, root cause analyses, and hardware diagnostic playbooks.

Zero spam. Unsubscribe anytime in 1 click.

Frequently Asked Questions: Fix CVE-2026-68820: Windows afd.sys Zero-Day Triage

What is CVE-2026-68820 and why is it dangerous?
CVE-2026-68820 is an actively exploited Use-After-Free (UAF) vulnerability in the Windows Ancillary Function Driver for WinSock (afd.sys). It allows a local, low-privileged attacker or malicious background process to escalate privileges directly to NT AUTHORITY\SYSTEM.
Is CVE-2026-68820 being exploited in the wild?
Yes. Microsoft MSRC and CISA confirmed active in-the-wild exploitation by advanced threat actors (including Lazarus Group) to bypass endpoint detection and deploy kernel-level rootkits.
Which Windows update fixes CVE-2026-68820?
The vulnerability is patched in the August 11, 2026 Patch Tuesday cumulative updates: KB5121003 for Windows 11 24H2, KB5041585 for Windows 11 23H2/22H2, KB5041580 for Windows 10 22H2, and KB5041578 for Windows Server 2022.
How do I verify if my endpoint is protected against CVE-2026-68820?
Run 'Get-HotFix -Id KB5121003, KB5041585, KB5041580' in elevated PowerShell or inspect the driver file version of C:\Windows\System32\drivers\afd.sys to ensure it reflects the August 2026 build release.

Official Technical References

  1. Microsoft Security Response Center (MSRC): CVE-2026-68820 Advisory — Microsoft MSRC
  2. CISA Known Exploited Vulnerabilities (KEV) Catalog — CISA
  3. Microsoft Learn: Windows Ancillary Function Driver Architecture — Microsoft Learn
Get Independent Tech Benchmarks First

Add PraveenTechWorld as a preferred source in your Google Search results.

Prefer on Google
P
Praveen

IT ops lead in India. I break Windows, Android and self-hosted AI stacks on my workbench, then write down what actually fixed them.

Explore more: Browse all security guides or check related articles below.