CVE-2026-68820: Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
CISA added CVE-2026-68820 to its Known Exploited Vulnerabilities catalog for a Windows Ancillary Function Driver for WinSock use-after-free that can allow local privilege elevation; apply vendor mitigations.
What changed
CISA added CVE-2026-68820 (Microsoft Windows Ancillary Function Driver for WinSock use-after-free) to its Known Exploited Vulnerabilities catalog on 2026-08-11 and set a remediation due date of 2026-08-25; NVD records affected Windows client and server releases and lists a CVSSv3.1 base score of 7.0.
Why it matters
The flaw is a local use-after-free that can let an authorized (low-privilege) user elevate privileges on affected Windows systems; NVD indicates active exploitation in SSVC metadata, so organizations should treat impacted assets as higher priority for mitigation or patching.
Who is affected
Affected products include multiple Windows client and server releases (Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 23H2, 24H2, 25H2, 26H1; Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025 and Server Core variants) with specific build upper bounds listed in the NVD; exact exposure in your environment depends on precise build numbers and whether vendor mitigations or updates have been applied—those details are not provided here.
What to do now
- Inventory Windows assets and map exact OS/build numbers against the NVD affected-version ranges before the listed fixes (use vendor guidance links in the CISA/NVD records).
- Apply Microsoft’s mitigations or updates per the MSRC guidance referenced by CISA (follow the MSRC/update-guide URL in the NVD/CISA notes).
- Prioritize remediation following CISA’s BOD 26-04 guidance and the CISA KEV due date of 2026-08-25; treat assets with internet exposure as higher priority.
- If mitigations or vendor patches are unavailable for cloud-hosted services, follow applicable BOD 26-04 guidance or discontinue use of the affected product as recommended by CISA.
- Prepare for post-incident handling by following CISA’s Forensics Triage Requirements referenced in the CISA catalog notes.
Technical scope and severity
NVD describes the issue as a use-after-free in the Windows Ancillary Function Driver for WinSock that allows a local authorized attacker to elevate privileges; NVD lists CWE-416 and assigns a CVSSv3.1 base score of 7.0 (AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
NVD SSVC metadata includes options indicating exploitation is 'active' and technical impact 'total'; CISA added the vulnerability to its KEV catalog on 2026-08-11 with a remediation due date of 2026-08-25.
Affected versions (per NVD)
NVD lists multiple affected Microsoft client and server releases and build ranges; examples include Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2–26H1), and Windows Server 2012 through 2025 (including Server Core variants).
Each product entry in NVD contains specific build lower/upper bounds indicating affected versions; organizations must compare their exact build numbers to those ranges to determine impact.
CISA and vendor guidance
CISA’s KEV entry directs stakeholders to apply mitigations per vendor instructions and to follow BOD 26-04 prioritization and Forensics Triage Requirements; the KEV notes include links to Microsoft’s advisory and NVD records.
Required actions in the KEV entry emphasize evaluating internet exposure, complying with BOD 26-04 for cloud services, or discontinuing use if mitigations are unavailable.
Questions and answers
Is this vulnerability being actively exploited?
According to the NVD SSVC data referenced by Microsoft/NVD, the option 'exploitation' is listed as 'active'; CISA added the vulnerability to its KEV catalog on 2026-08-11.
Can this be exploited remotely over the network?
NVD’s CVSS vector indicates the attack vector is LOCAL; the CISA catalog description also states the issue allows local privilege elevation, so network remote exploitation is not indicated in these sources.
Does this affect all Windows releases?
No—NVD provides specific affected Windows releases and build upper bounds; only systems with builds earlier than the listed fixed builds are marked as affected.
Primary sources
- CISA Known Exploited Vulnerabilities Catalog
- Microsoft advisory
- NIST National Vulnerability Database record
Evidence note: Information is limited to the CISA KEV entry and NVD record; there are no vendor-published exploit or mitigation details included in these extracts beyond links referenced in the sources.