CVE-2026-68820
HIGH KEVWindows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Title source: cnaExploitation Summary
CVE-2026-68820 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added August 11, 2026.
Description
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
References (2)
Core 2
Core References
Vendor Advisory vendor-advisory
patch
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68820
Third Party Advisory, US Government Resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-68820
Scores
CVSS v3
7.0
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
active
Automatable
no
Technical Impact
total
Details
CISA KEV
2026-08-11
VulnCheck KEV
2026-08-11
ENISA EUVD
EUVD-2026-56468
CWE
CWE-416
Status
published
Products (23)
Microsoft/Windows 10 Version 1607
10.0.14393.0 - 10.0.14393.9418
Microsoft/Windows 10 Version 1809
10.0.17763.0 - 10.0.17763.9115
Microsoft/Windows 10 Version 21H2
10.0.19044.0 - 10.0.19044.7663
Microsoft/Windows 10 Version 22H2
10.0.19045.0 - 10.0.19045.7663
Microsoft/Windows 11 version 23H2
10.0.22631.0 - 10.0.22631.7517
Microsoft/Windows 11 Version 24H2
10.0.26100.0 - 10.0.26100.9168
Microsoft/Windows 11 Version 25H2
10.0.26200.0 - 10.0.26200.9168
Microsoft/Windows 11 version 26H1
10.0.28000.0 - 10.0.28000.2704
Microsoft/Windows Server 2012
6.2.9200.0 - 6.2.9200.26279
Microsoft/Windows Server 2012
6.2.9200.0 - 6.2.9200.26280
... and 13 more
Published
Aug 11, 2026
KEV Added
Aug 11, 2026
Tracked Since
Aug 11, 2026