CVE-2026-68820
9.5 CISA KEVMicrosoft · Windows Ancillary Function Driver for WinSock
A use-after-free vulnerability in the Microsoft Windows Ancillary Function Driver for WinSock is currently being exploited in the wild.
Executive summary
A critical use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock is under active exploitation, presenting a severe risk to Windows systems.
Vulnerability
This is a use-after-free vulnerability within the driver, requiring an authenticated local user to trigger the flaw.
Business impact
Exploitation allows for local privilege escalation and potential system compromise, which could lead to full loss of system confidentiality, integrity, and availability. With a CVSS score of 9.5 and confirmed active exploitation, this flaw poses a severe risk to the stability and security of internal workstation and server fleets.
Remediation
Immediate Action: Update all affected Windows systems to the versions specified in the Microsoft security update guide.
Proactive Monitoring: Review system logs for signs of anomalous driver activity or unexpected system crashes that could indicate a failed exploitation attempt.
Compensating Controls: Implement robust endpoint detection and response solutions to identify and block unauthorized privilege escalation attempts.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the confirmed active exploitation, immediate patch deployment is mandatory for all affected Windows environments. Security teams should verify that all endpoints have successfully ingested the latest security updates to neutralize this high-risk threat.