Knox CVE Database
/
CVE-2026-68820
High
7.0

CVE-2026-68820: Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability

Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.

Added to the CISA KEV catalog:
August 11, 2026

Overview

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Vulnerability details

Affected vendor
Microsoft
Affected product
Windows Ancillary Function Driver for WinSock
Weakness type (CWE)
CWE-416

The Windows Ancillary Function Driver for WinSock (afd.sys) is a kernel-mode driver that mediates socket operations between user-mode applications and the Windows networking stack. A use-after-free flaw (CWE-416) exists when a kernel object managed by this driver is freed while a stale reference to it remains accessible. Because afd.sys operates in kernel space, any subsequent access through that dangling pointer can corrupt kernel memory, overwrite adjacent structures, or redirect execution flow to attacker-controlled data, making this class of flaw a reliable path to privilege escalation when reliably triggered.


An attacker who already holds a standard user account on the target system can submit a crafted sequence of socket API calls through the WinSock Ancillary Function Driver to trigger the use-after-free condition in kernel memory. Successful exploitation yields local privilege escalation to a higher-privileged context, with full confidentiality, integrity, and availability impact on the local machine. The high attack complexity rating reflects that exploitation requires conditions beyond the attacker's direct control, such as specific heap state or precise timing, meaning reliable exploitation demands preparation effort rather than a simple one-shot call sequence.

Severity and impact

7.0
High
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack vector
Local
Attack complexity
High
Privileges required
Low
User interaction
None
Scope
Unchanged
Confidentiality impact
High
Integrity impact
High
Availability impact
High

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Monitor for low-privileged processes spawning or injecting into high-privileged processes without a corresponding elevation event (UAC prompt, explicit token assignment), which may indicate a successful kernel privilege escalation via afd.sys.
  • Review Windows Security event logs for token privilege changes (Event ID 4703) or new process creation (Event ID 4688) where a standard-user process acquires SYSTEM-level privileges without a matching administrative logon session.
  • Audit kernel crash dumps or minidumps referencing afd.sys in the faulting module field; repeated bugchecks in this driver on a host with low-privileged interactive users warrant investigation as failed exploitation attempts.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see References) guidance and CISA’s “Forensics Triage Requirements” (see References). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
August 25, 2026

Additional hardening

  • Apply Microsoft's security updates: Windows 10 21H2/22H2 to build 10.0.19044.7663 / 10.0.19045.7663 or later, Windows 11 23H2 to 10.0.22631.7517 or later, and Windows Server 2016/2019/2022 to their respective fixed builds listed in the vendor advisory under References.
  • Restrict interactive and remote logon rights to only accounts that require them; a standard user account is the required precondition, so reducing the population of users who can log on locally or via RDP directly limits exposure.
  • Deploy Windows Defender Credential Guard and Kernel Data Protection where supported; these controls raise the bar for kernel memory manipulation and may impede reliable heap-shaping required by high-complexity UAF exploits.
  • Apply Attack Surface Reduction rules and enable kernel-mode hardware-enforced stack protection (HVCI) on supported hardware to constrain the memory regions an attacker can use to reclaim freed kernel objects.

Key dates

Published (NVD)
August 11, 2026
Added to CISA KEV
August 11, 2026
Remediation deadline
August 25, 2026
Last updated
August 16, 2026

References

Frequently asked questions

Does CVE-2026-68820 affect my FedRAMP authorization?

If Microsoft Windows Ancillary Function Driver for WinSock runs inside your authorization boundary, CVE-2026-68820 is a direct concern for your Federal Risk and Authorization Management Program (FedRAMP) authorization. CISA's Known Exploited Vulnerabilities (KEV) catalog lists this vulnerability with a remediation deadline of August 25, 2026. An unpatched KEV within your boundary is an assessor finding. You must either remediate it or formally document a mitigation before your assessor and sponsoring agency raise it.

How does Knox help me handle CVE-2026-68820?

Remediating Microsoft Windows Ancillary Function Driver for WinSock is your responsibility under the FedRAMP shared-responsibility model. Knox does not patch your software. What Knox provides is the pre-authorized, single-tenant boundary in which you carry out that remediation, plus Knox's automated continuous monitoring platform and audit-artifact coverage to help you document the fix for your next assessment. The patch is yours to apply; maintaining a compliant posture while you apply it is not something you manage alone.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues, including CVE-2026-68820. Exposure surfaces during ongoing monitoring rather than only when an assessor flags it at review time, giving you the lead time to act before a finding becomes a formal problem.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

What happens if CVE-2026-68820 isn't remediated by August 25, 2026?

Missing the August 25, 2026 deadline turns CVE-2026-68820 into a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what converts a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Remediating on time keeps your authorization clean and the agency relationship intact.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.

Book a Meeting