About:
CVE-2026-68820 is a local elevation of privilege vulnerability affecting the Windows Ancillary Function Driver for WinSock (AFD.sys), the kernel-mode driver responsible for handling socket operations for Windows networking.
The vulnerability is caused by a use-after-free condition that allows a locally authenticated attacker with low privileges to trigger a race condition through a specially crafted application. Successful exploitation enables privilege escalation to SYSTEM without requiring user interaction.
Microsoft confirmed CVE-2026-68820 as a zero-day actively exploited in the wild at the time of disclosure. Exploitation requires an attacker to already have a foothold on the target system.
RedLegg will occasionally communicate vulnerabilities released outside the usual release schedule to provide additional value to our customers. These emergency bulletins describe vulnerabilities or threats we classify as the highest severity level and warrant out-of-band emergency patching or mitigation action.
Identifier: CVE-2026-68820
PoC or Exploitation:
CVSS Score: 7.0 base / 6.1 temporal (Important, CVSS v3.1)
Update / Patch:
Description:
Mitigation Recommendation: