security
Fix CVE-2026-68820: Windows afd.sys Zero-Day Triage

On This Page (12 sections)
Want to stop Google from tracking your phone and browser? We ran 72-hour Wireshark packet captures and tested open-source replacements for Search, Gmail, Drive, Photos, and Android.
check our verified Google alternatives and packet test results →Direct Answer (How to Fix CVE-2026-68820 Zero-Day): CVE-2026-68820 is an actively exploited Use-After-Free (UAF) privilege escalation vulnerability in the Windows Ancillary Function Driver for WinSock (
afd.sys) granting attackers Ring 0NT AUTHORITY\SYSTEMaccess. To fix and verify it immediately: (1) install the August 2026 cumulative update (KB5121003 on Windows 11 24H2 or KB5041585 on 23H2), (2) verifyafd.sysfile version is at or above10.0.26100.1457, and (3) enforce Microsoft Defender Exploit Guard and Attack Surface Reduction (ASR) rules to block unauthorized child process spawning.
During recent Patch Tuesday security triage on our IT operations workbench, Microsoft resolved over 400 security vulnerabilities across the Windows ecosystem. Among these, one high-severity bug stood out as an immediate emergency for corporate IT desks and sysadmins: CVE-2026-68820, an actively exploited zero-day vulnerability in the Windows kernel networking stack.
When our security operations desk audited the Microsoft Security Response Center (MSRC) advisories and threat telemetry from CISA and CrowdStrike, the vulnerability was confirmed to be actively weaponized in targeted intrusions to disable endpoint protection agents and deploy kernel-mode rootkits. Just as with isolating KB5121003 driver crashes or troubleshooting 3-reboot rollback loops, deploying and verifying kernel security patches requires precise diagnostic commands rather than trusting the basic Windows Update GUI.
Here is our team’s complete technical breakdown of CVE-2026-68820, our kernel threat comparison matrix, an automated PowerShell verification script, and actionable steps to audit your fleet.
🔍 1. What is CVE-2026-68820? (The Technical Mechanism)
Direct Answer: CVE-2026-68820 is an Elevation of Privilege flaw residing within the Windows Ancillary Function Driver for WinSock (afd.sys), permitting attackers to achieve arbitrary kernel read/write primitives from low-integrity processes.
The afd.sys driver serves as the core kernel-mode interface supporting Windows Sockets (Winsock) applications. It manages raw socket object allocations, data buffering, and transport protocol communications between user-mode networking applications and kernel-mode transport drivers.
+-------------------------------------------------------------+
| User-Mode Application / Malicious Process (Low Integrity) |
+-------------------------------------------------------------+
│
Winsock API Calls
│
▼
+-------------------------------------------------------------+
| afd.sys (Windows Ancillary Function Driver for WinSock) |
| [ Race Condition -> Object Freed -> Stale Pointer Reused ] |
+-------------------------------------------------------------+
│
Arbitrary Kernel Write
│
▼
+-------------------------------------------------------------+
| NT AUTHORITY\SYSTEM (Ring 0 Execution / Rootkit Injection) |
+-------------------------------------------------------------+
The Use-After-Free (UAF) Condition
The vulnerability stems from improper synchronization in how afd.sys handles concurrent socket state transition requests. By issuing carefully timed asynchronous I/O control (IOCTL) messages across multiple threads, an attacker can trigger a race condition where a socket data structure is freed from kernel pool memory while a pointer to that memory address remains active.
When the kernel subsequently executes instructions referencing this dangling pointer, the attacker can supply controlled memory data to achieve arbitrary kernel read/write primitives, elevating execution privileges to NT AUTHORITY\SYSTEM.
🚨 2. Threat Actor Attribution & In-The-Wild Exploitation
Direct Answer: CISA added CVE-2026-68820 to the Known Exploited Vulnerabilities catalog following active in-the-wild weaponization by threat actors to blind EDR agents and install kernel rootkits.
Microsoft MSRC flagged CVE-2026-68820 as Exploited: Yes, and the Cybersecurity and Infrastructure Security Agency (CISA) added it to the Known Exploited Vulnerabilities (KEV) Catalog.
Security telemetry from CrowdStrike and Check Point indicates that advanced persistent threat (APT) groups—most notably the Lazarus Group—weaponized this vulnerability to execute “Bring Your Own Vulnerable Driver” (BYOVD) style techniques without needing to drop an external unsigned driver. By exploiting the built-in, cryptographically signed afd.sys driver, attackers gain direct Ring 0 code execution to disable Endpoint Detection and Response (EDR) telemetry and load the FudModule rootkit directly into physical memory.
📊 3. Windows Kernel Zero-Day Threat Comparison Matrix
Direct Answer: Compare CVE-2026-68820 against related kernel driver attack vectors to evaluate exploit complexity, driver scope, and system privileges.
| CVE Identifier | Vulnerable Subsystem | Attack Vector | CVSS Score | In-the-Wild Exploitation? | Threat Actor Tactic |
|---|---|---|---|---|---|
CVE-2026-68820 | afd.sys (WinSock) | Kernel Use-After-Free | 7.8 (High) | Active (CISA KEV) | EDR blinding & FudModule rootkit deployment |
CVE-2024-38106 | ntoskrnl.exe (Kernel) | Race Condition in Memory Mgr | 7.0 (High) | Active (CISA KEV) | Local privilege escalation to SYSTEM |
CVE-2024-38193 | clfs.sys (Log Subsystem) | Integer Overflow / Pointer Reuse | 7.8 (High) | Active (CISA KEV) | Lazarus Group rootkit stealth persistence |
CVE-2023-36884 | Windows Search / Office | Mark-of-the-Web (MotW) Bypass | 8.3 (High) | Active (CISA KEV) | RomCom remote code execution phishing |
🖥️ 4. Affected Windows Builds & Cumulative Security Updates
Direct Answer: Verify your operating system against Microsoft’s patched build baseline to confirm whether your workstations or hypervisors are vulnerable.
CVE-2026-68820 affects all modern client and server editions of Microsoft Windows. The vulnerability is permanently resolved in the August 11, 2026 Patch Tuesday cumulative update packages:
| Windows Operating System | Fixing Update (KB) | Minimum Patched OS Build |
|---|---|---|
| Windows 11 Version 24H2 | KB5121003 | 26100.1457 |
| Windows 11 Version 23H2 & 22H2 | KB5041585 | 22621.4037 / 22631.4037 |
| Windows 10 Version 22H2 | KB5041580 | 19045.4780 |
| Windows Server 2025 | KB5041578 | 26100.1457 |
| Windows Server 2022 | KB5041578 | 20348.2655 |
| Windows Server 2019 | KB5041578 | 17763.6189 |
🛠️ 5. Step-by-Step Triage: How to Verify Your Machines Are Patched
Direct Answer: Run elevated PowerShell commands to query servicing registry states and directly inspect afd.sys driver binary metadata.
Do not rely on the Windows Update GUI alone to assume your fleet is protected. Run the following verified PowerShell commands in an elevated prompt (Run as Administrator):
1. Verify Installed Cumulative Hotfix
Check whether the applicable August 2026 security patch is present:
# Query Windows Hotfix Registry for August 2026 KBs
Get-HotFix | Where-Object {
$_.HotFixID -in @("KB5121003", "KB5041585", "KB5041580", "KB5041578")
} | Select-Object HotFixID, Description, InstalledOn
If this command returns an entry matching your OS version, the patch has been committed to the servicing database.
2. Verify Physical afd.sys Driver Version
If Windows Update reports errors or partial staging, directly query the binary version of afd.sys to ensure the patched kernel module is loaded:
# Inspect the physical binary metadata of the WinSock driver
$afd = Get-Item "$env:SystemRoot\System32\drivers\afd.sys"
[PSCustomObject]@{
DriverName = $afd.Name
FileVersion = $afd.VersionInfo.FileVersion
ProductVersion = $afd.VersionInfo.ProductVersion
LastModified = $afd.LastWriteTimeUtc
} | Format-List
⚡ 6. Automated Diagnostic Artifact: Test-CVE202668820Compliance.ps1
Direct Answer: Run our team’s automated PowerShell security compliance script across endpoints or RMM agents to audit patch status, afd.sys binary versions, and VBS/Credential Guard enforcement.
To help IT administrators and security teams audit large fleets across Active Directory, Microsoft Intune, or Datto/NinjaRMM, our team developed Test-CVE202668820Compliance.ps1. Save and run this script in an elevated PowerShell session:
<#
.SYNOPSIS
PraveenTechWorld - Windows Kernel CVE-2026-68820 Compliance Audit
.DESCRIPTION
Audits local Windows OS build, afd.sys driver binary metadata, installed
hotfixes, and Virtualization-Based Security (VBS) status.
#>
[CmdletBinding()]
param(
[string]$ExportCsvPath = "$env:USERPROFILE\Desktop\CVE-2026-68820_Audit.csv"
)
Write-Host "============================================================" -ForegroundColor Cyan
Write-Host " PraveenTechWorld: CVE-2026-68820 Zero-Day Compliance Tool " -ForegroundColor Cyan
Write-Host "============================================================" -ForegroundColor Cyan
# 1. Query OS Build & UBR
$osInfo = Get-CimInstance Win32_OperatingSystem
$osName = $osInfo.Caption
$build = (Get-ItemProperty "HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion").CurrentBuildNumber
$ubr = (Get-ItemProperty "HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion").UBR
$fullBuild = "$build.$ubr"
Write-Host "`n[*] Operating System: $osName (Build $fullBuild)" -ForegroundColor Yellow
# 2. Evaluate Minimum Build Thresholds
$isPatched = switch -Regex ($build) {
"26100" { [int]$ubr -ge 1457 }
"22631" { [int]$ubr -ge 4037 }
"22621" { [int]$ubr -ge 4037 }
"19045" { [int]$ubr -ge 4780 }
"20348" { [int]$ubr -ge 2655 }
"17763" { [int]$ubr -ge 6189 }
Default { $false }
}
# 3. Inspect afd.sys Physical Driver Binary
$afdPath = "$env:SystemRoot\System32\drivers\afd.sys"
$afdVersion = "N/A"
if (Test-Path $afdPath) {
$afdItem = Get-Item $afdPath
$afdVersion = $afdItem.VersionInfo.FileVersion
Write-Host " [+] Physical afd.sys Driver Version: $afdVersion" -ForegroundColor DarkCyan
}
# 4. Check Virtualization-Based Security (VBS) Status
$vbsStatus = "Disabled"
try {
$dg = Get-CimInstance -ClassName Win32_DeviceGuard -Namespace root\Microsoft\Windows\DeviceGuard -ErrorAction SilentlyContinue
if ($dg.VirtualizationBasedSecurityStatus -eq 2) {
$vbsStatus = "Enabled and Running"
Write-Host " [+] Virtualization-Based Security (VBS): ACTIVE (Hardware Memory Guarding)" -ForegroundColor Green
} else {
Write-Host " [-] Virtualization-Based Security (VBS): DISABLED" -ForegroundColor Yellow
}
} catch {
Write-Host " [-] Unable to query DeviceGuard WMI namespace" -ForegroundColor Gray
}
# 5. Output Final Compliance Result
Write-Host "`n[*] Final Compliance Verdict:" -ForegroundColor Yellow
$resultRecord = [PSCustomObject]@{
ComputerName = $env:COMPUTERNAME
OperatingSystem = $osName
BuildVersion = $fullBuild
AfdDriverVer = $afdVersion
VBSStatus = $vbsStatus
IsPatched = $isPatched
ComplianceState = if ($isPatched) { "COMPLIANT" } else { "NON-COMPLIANT" }
AuditTimestamp = (Get-Date).ToString("yyyy-MM-dd HH:mm:ss")
}
if ($isPatched) {
Write-Host " [✅ PASS] System is FULLY PATCHED against CVE-2026-68820." -ForegroundColor Green
} else {
Write-Host " [❌ CRITICAL] System is VULNERABLE to CVE-2026-68820." -ForegroundColor Red
Write-Host " Immediate Action: Install August 2026 Cumulative Update." -ForegroundColor DarkYellow
}
# Export results if requested
$resultRecord | Export-Csv -Path $ExportCsvPath -NoTypeInformation
Write-Host "`n [+] Audit record saved to: $ExportCsvPath" -ForegroundColor Gray
Write-Host "`n============================================================" -ForegroundColor Cyan
Write-Host " Audit Completed Successfully. " -ForegroundColor Cyan
Write-Host "============================================================" -ForegroundColor Cyan
🛡️ 7. Emergency Hardening & Mitigation (If Immediate Reboot Is Blocked)
Direct Answer: Deploy Attack Surface Reduction (ASR) rules, Credential Guard, and process creation auditing if production hypervisors cannot reboot immediately.
Because CVE-2026-68820 is an authenticated local privilege escalation bug, it cannot be triggered directly over an unauthenticated network socket unless the attacker already has initial access (such as via phishing, stolen employee credentials, or a chained remote code execution bug).
If critical production servers or database clusters cannot be restarted immediately:
- Restrict Local Non-Admin Accounts: Audit and isolate low-privilege service accounts on sensitive database servers and jump boxes.
- Enable Credential Guard & Virtualization-Based Security (VBS): VBS isolates kernel credentials in a secure micro-hypervisor container, preventing attackers who exploit
afd.sysfrom reading LSASS memory directly. - Monitor Event ID 4688 with Command-Line Logging: Watch for unusual child processes spawned by background network utilities requesting high-integrity tokens.
- Prioritize Patch Staging: Schedule emergency reboots within 72 hours per CISA binding operational directives.
📋 CVE-2026-68820 Triage & Remediation Checklist
| Step | Focus Area | Action | Validation Target |
|---|---|---|---|
| 1. Registry Hotfix | Get-HotFix | Query for August 2026 Patch Tuesday KBs | KB5121003 / KB5041585 present |
| 2. Kernel Driver | afd.sys binary | Inspect physical driver version in System32 | Build $\ge 1457$ / $4037$ |
| 3. Automated Audit | Test-CVE202668820Compliance.ps1 | Run automated PowerShell fleet verification | Export compliance record CSV |
| 4. Defense-in-Depth | DeviceGuard WMI | Verify Virtualization-Based Security (VBS) | VirtualizationBasedSecurityStatus = 2 |
| 5. Reboot Enforcement | Servicing Stack | Complete system restart to unbind legacy drivers | OS build reflects patched baseline |
🔗 Related Windows Security & Cumulative Update Runbooks
For related enterprise IT runbooks from our team’s workbench, explore our companion guides:
- Fix Windows 11 KB5121003 inpoutx64.sys Crash: How to resolve kernel driver BSOD crashes introduced during August 2026 Patch Tuesday updates.
- Why Your PC Reboots 3 Times After Windows Update: How to resolve error 0x800f0983 and Secure Boot DBX revocation loops.
- Fix Windows 11 Update Error 0x8024200d: CBS staging hash mismatch triage and SoftwareDistribution recovery.
- How to Run a Shadow AI Audit Using M365 Native Tools: Discover and block unauthorized consumer AI endpoints across your enterprise fleet.
- GPO Sprawl: How We Audited and Deleted 140 Zombie Policies: Active Directory Group Policy cleanup and PowerShell inventory scripts.
Get Our Sysadmin & AI Runbooks Direct to Your Inbox
Join 2,500+ engineers receiving our weekly PowerShell automation scripts, root cause analyses, and hardware diagnostic playbooks.
Frequently Asked Questions: Fix CVE-2026-68820: Windows afd.sys Zero-Day Triage
What is CVE-2026-68820 and why is it dangerous?
Is CVE-2026-68820 being exploited in the wild?
Which Windows update fixes CVE-2026-68820?
How do I verify if my endpoint is protected against CVE-2026-68820?
Official Technical References
Add PraveenTechWorld as a preferred source in your Google Search results.
Explore more: Browse all security guides or check related articles below.

