CVE-2026-68820 · Low · CISA KEV
CVE-2026-68820: Windows AFD Use-After-Free Allows Local Privilege Escalation
Threat Engine Auto-Feed · data current as of 2026-08-12
CVE-2026-68820 is a use-after-free vulnerability in the Microsoft Windows Ancillary Function Driver for WinSock. This flaw allows an authorized local attacker to elevate privileges. It has been added to CISA's KEV catalog, indicating active exploitation in the wild.
- CVSS:
- EPSS percentile:
- Exploitation pressure: 25/100 (Low)
Exploitation reality: listed in CISA KEV (exploited in the wild). Threat × Vulnerability from public signals — impact depends on your environment.
Weakness —
A use-after-free vulnerability occurs when a program tries to use memory that has already been freed. This can lead to unpredictable behavior, including crashes or, in this case, allowing an attacker to execute malicious code with elevated privileges.
Who's at risk
Exposure: unknown · Auth: unknown · unknown
Enterprise profiles most at risk
- Organizations running Microsoft Windows systems where local user access is possible, especially in environments with shared workstations or remote desktop services.
- Financial services, due to documented targeting by financially motivated groups like FIN7, LockBit affiliates, and APT38.
- Technology sector, given assessed targeting by groups like APT29 and Scattered Spider, who focus on supply-chain and identity-based attacks.
Misconfigurations that escalate it
- Any setup that grants unauthorized or excessive local access to systems, increasing the attack surface for authorized attackers.
High-impact scenarios
- An attacker with initial low-level access gaining SYSTEM-level privileges on a compromised Windows machine, enabling full control over the system.
- Lateral movement within a network, as an attacker can escalate privileges on internal systems to further their objectives.
- Data exfiltration or system disruption if an attacker leverages elevated privileges to access sensitive information or tamper with critical services.
Likely adversaries
- FIN7 — Financial services (Assessed)
- LockBit affiliates — Financial services (Assessed)
- APT38 (Lazarus) — Financial services (Assessed)
- APT29 (Cozy Bear) — Technology (Assessed)
- Scattered Spider — Technology (Assessed)
What to do (defensive)
Detect
- Monitor for unusual process activity or privilege escalation attempts originating from standard user accounts on Windows systems.
- Implement endpoint detection and response (EDR) solutions to identify anomalous behavior related to memory access and driver interactions.
Contain
- Isolate affected systems from the network to prevent further compromise and lateral movement.
- Review and restrict local user permissions to the absolute minimum necessary across all Windows endpoints.
Patch
- Apply vendor-provided security updates for Microsoft Windows Ancillary Function Driver for WinSock as soon as they become available.
Frontier verdict — Low
This vulnerability is critical due to its presence in CISA KEV, indicating active exploitation, and its potential for local privilege escalation on widely used Windows systems.
For detection-engineering and awareness only · point-in-time · not security advice · sourced from NVD, FIRST EPSS, CISA KEV. Adversary mappings are assessments unless cited.