Skip to content

Microsoft’s August Patch Tuesday: Lazarus Exploited Kernel Zero-Day in afd.sys

In brief: The actively exploited vulnerability CVE-2026-68820 in the Windows kernel driver afd.sys allowed Lazarus to escalate privileges to SYSTEM level, while four other critical vulnerabilities rated CVSS 9.8 were exploitable without any user interaction.

Microsoft closed hundreds of vulnerabilities in its August Patch Tuesday. One of them, CVE-2026-68820 in the network driver afd.sys, had already been used as a zero-day for privilege escalation by the North Korea-linked group Lazarus.

The actively exploited vulnerability CVE-2026-68820 (CVSS 7.0) affects afd.sys, the Ancillary Function Driver for WinSock — a central kernel driver through which practically every network connection under Windows passes. It is a use-after-free flaw: an attacker already logged in locally can trigger a race condition via a crafted application and gain SYSTEM privileges without any further user interaction. The vulnerability was reported by Check Point researchers Moshe Marelus and David Driker and was already being actively exploited as a zero-day at the time it was reported. According to Check Point Research, the Lazarus group used the vulnerability as part of its Operation Dream Job campaign, in which targets are lured with fake job offers — most recently focusing primarily on the defense sector in Europe and India. Using a crafted PDF application called SecurityPDF and a newly discovered backdoor named Troy, the attackers first gained access and then leveraged the Windows vulnerability to run a new version of their kernel rootkit FudModule with SYSTEM privileges. According to security researchers, three other zero-day vulnerabilities in the same driver have been actively exploited since 2022, including one from 2024 likewise attributed to Lazarus.

For CISOs, it is relevant that afd.sys is a recurring target for privilege escalation — the fourth actively exploited vulnerability in this driver since 2022. Attack chains that begin with social engineering (fake job offers, crafted PDFs) and subsequently deploy kernel exploits for privilege escalation require, in addition to patch management, endpoint detection measures capable of identifying suspicious local process activity and race-condition patterns. Lazarus’s continued focus on defense companies in Europe and India should be weighted accordingly in threat intelligence assessments.

In addition, Microsoft closed four further vulnerabilities, each rated at the maximum score of 9.8, for which neither a user account nor victim interaction is required for exploitation: in Windows DNS Server, Windows Deployment Services, Microsoft’s implementation of the QUIC transport protocol, and the High Performance Computing Pack. None of these four vulnerabilities were considered actively exploited at the time of publication. The Zero Day Initiative puts the total scope of this Patch Tuesday, independent of Microsoft’s own count, at 398 new CVE entries, of which 62 are rated critical, while Microsoft itself and several trade publications report a total of 421 CVE entries.

The August Patch Tuesday also closes the second half of an attack chain against on-premises SharePoint installations that was partially fixed back in July. Security researchers from Rapid7 had already reported to Microsoft in May a combination of an authentication bypass and a separate code execution vulnerability that allowed arbitrary code execution without prior login. In July, Microsoft first closed the authentication bypass tracked as CVE-2026-55040, which allowed a remote, unauthenticated attacker to impersonate any SharePoint user or administrator, provided their identity was known to the attacker. In August, the associated code execution vulnerability followed, tracked as CVE-2026-63520. Operators of on-premises SharePoint farms should ensure that both the July and August updates are installed, since only the combination of both patches fully closes the attack chain.


Source: www.it-daily.net · Published August 13, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.

Share on: