CVE-2026-68820

HIGH KEV

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

Title source: cna
STIX 2.1

Exploitation Summary

CVE-2026-68820 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added August 11, 2026.

Description

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory patch
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68820

Scores

CVSS v3 7.0
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2026-08-11
VulnCheck KEV 2026-08-11
ENISA EUVD EUVD-2026-56468
CWE
CWE-416
Status published
Products (23)
Microsoft/Windows 10 Version 1607 10.0.14393.0 - 10.0.14393.9418
Microsoft/Windows 10 Version 1809 10.0.17763.0 - 10.0.17763.9115
Microsoft/Windows 10 Version 21H2 10.0.19044.0 - 10.0.19044.7663
Microsoft/Windows 10 Version 22H2 10.0.19045.0 - 10.0.19045.7663
Microsoft/Windows 11 version 23H2 10.0.22631.0 - 10.0.22631.7517
Microsoft/Windows 11 Version 24H2 10.0.26100.0 - 10.0.26100.9168
Microsoft/Windows 11 Version 25H2 10.0.26200.0 - 10.0.26200.9168
Microsoft/Windows 11 version 26H1 10.0.28000.0 - 10.0.28000.2704
Microsoft/Windows Server 2012 6.2.9200.0 - 6.2.9200.26279
Microsoft/Windows Server 2012 6.2.9200.0 - 6.2.9200.26280
... and 13 more
Published Aug 11, 2026
KEV Added Aug 11, 2026
Tracked Since Aug 11, 2026