PT-2026-70737 · Microsoft · Windows Ancillary Function Driver For Winsock+1
CVE-2026-68820
·
Published
2026-07-28
·
Updated
2026-09-11
CVSS v3.1
7.0
High
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows (affected versions prior to August 2026)
Description
A use-after-free condition exists in the Windows Ancillary Function Driver for WinSock (
afd.sys). This issue occurs due to unreliable pointer dereferencing within the Windows kernel. An authorized local attacker can exploit this flaw to elevate their privileges to the SYSTEM level.Real-world exploitation has been documented as part of Operation Dream Job by the Lazarus Group, targeting organizations in the global defense and aerospace sectors. The attackers used spear-phishing via professional social networks to distribute trojanized applications, such as SecurityPDF, to gain an initial foothold. Once inside, they exploited this flaw to deploy FudModule, a kernel-mode rootkit, and the Troy backdoor for remote access and information gathering. The attack chain also involved the MISTPEN loader, which utilized the Microsoft Graph API to retrieve malicious modules from OneDrive.
Recommendations
Update Microsoft Windows to the version released in the August 2026 Patch Tuesday update.
Perform a system reboot after installing the update to ensure the vulnerable kernel driver is replaced and no longer loaded in memory.
Exploit
Fix
LPE
RCE
DoS
Untrusted Pointer Dereference
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Windows
Windows Ancillary Function Driver For Winsock