Microsoft Patches Actively Exploited Windows WinSock Vulnerability


microsoft researcher legal
Image credit: Microsoft

Microsoft has released a security fix for an actively exploited Windows vulnerability that can allow authenticated attackers to gain SYSTEM privileges.

The flaw, tracked as CVE-2026-68820, affects the Windows Ancillary Function Driver for WinSock and was patched as part of the August 2026 Patch Tuesday updates.

Attackers can gain SYSTEM privileges

CVE-2026-68820 is a local privilege escalation vulnerability with a CVSS score of 7.0, placing it in the high-severity category.

An attacker who already has local authentication can run a specially crafted application to trigger the flaw. Successful exploitation can elevate the attacker to SYSTEM privileges, giving them extensive control over the affected Windows device.

Microsoft says the attack requires no user interaction. However, exploitation complexity remains relatively high because attackers may need specific information about the target environment or additional preparation before they can reliably trigger the vulnerability.

Despite those requirements, Microsoft has confirmed that attackers are already exploiting CVE-2026-68820 in the wild.

Windows 10, Windows 11, and Windows Server are affected

The vulnerability affects a broad range of Microsoft operating systems.

Affected releases include Windows 10 versions from 1607 through 22H2, as well as Windows 11 versions 23H2 through 26H1.

Windows Server installations are also vulnerable, with affected versions ranging from Windows Server 2012 through Windows Server 2025.

Microsoft has released updates for supported affected systems. The company has not provided a registry-based mitigation or alternative workaround, making installation of the relevant security update the primary fix.

Microsoft addresses hundreds of security flaws

The WinSock vulnerability arrived alongside a particularly large security release. Microsoft fixed around 400 flaws in the August 2026 Patch Tuesday.

Microsoft has also faced other recent security issues. The ShieldBreak zero-day can grant SYSTEM access on fully patched Windows systems, while the company recently exposed the infrastructure behind DeadLock ransomware.

Via Neowin

More about the topics: microsoft, security

Readers help support Windows Report. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more

User forum

0 messages