Exploited WinSock driver flaw tops Microsoft’s 398-fix August release

Microsoft's August update batch closes 398 flaws led by a WinSock driver zero-day already under attack.

CSBadmin
2 Min Read

Microsoft’s August update cycle closes 398 vulnerabilities, and the one already under attack sits deep in the Windows network stack. The active-exploitation flag belongs to a driver bug tied to North Korean espionage.

Tracked as CVE-2026-68820 (CVSS 7.0), the flaw is a use-after-free in afd.sys, the Ancillary Function Driver behind Windows socket operations. It depends on a race condition, and Check Point Research attributes its use to Lazarus Group’s Operation Dream Job lure campaign, which recruits targets through fake job offers.

The exploit path starts with code already running on a machine. From there an attacker can raise privileges to SYSTEM, which is why Microsoft marks the bug as exploited even though the base score sits lower than several peers in the release.

Four more flaws ask nothing of the victim at all. No account, no password, no click. They hit Windows DNS Server, Windows Deployment Services, Microsoft’s QUIC transport, and High Performance Computing Pack, each rated CVSS 9.8 for unauthenticated remote code execution on servers. None carried an exploited flag at ship time.

By the Zero Day Initiative’s tally, 62 of the 398 fixes rank as Critical. The batch also completes a SharePoint chain, closing the RCE half after the authentication bypass was patched in July, so on-premises farms need both updates.

For patching order, the driver zero-day goes first, followed by the four 9.8 server flaws. Those give an attacker code on a server without any user action.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.