PT-2026-70737 · Microsoft · Windows Ancillary Function Driver For Winsock+1

CVE-2026-68820

·

Published

2026-07-28

·

Updated

2026-09-11

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Windows (affected versions prior to August 2026)
Description A use-after-free condition exists in the Windows Ancillary Function Driver for WinSock (afd.sys). This issue occurs due to unreliable pointer dereferencing within the Windows kernel. An authorized local attacker can exploit this flaw to elevate their privileges to the SYSTEM level.
Real-world exploitation has been documented as part of Operation Dream Job by the Lazarus Group, targeting organizations in the global defense and aerospace sectors. The attackers used spear-phishing via professional social networks to distribute trojanized applications, such as SecurityPDF, to gain an initial foothold. Once inside, they exploited this flaw to deploy FudModule, a kernel-mode rootkit, and the Troy backdoor for remote access and information gathering. The attack chain also involved the MISTPEN loader, which utilized the Microsoft Graph API to retrieve malicious modules from OneDrive.
Recommendations Update Microsoft Windows to the version released in the August 2026 Patch Tuesday update. Perform a system reboot after installing the update to ensure the vulnerable kernel driver is replaced and no longer loaded in memory.

Exploit

Fix

LPE

RCE

DoS

Untrusted Pointer Dereference

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-11398
BDU:2026-11889
CVE-2026-68820

Affected Products

Windows
Windows Ancillary Function Driver For Winsock