CVE-2026-68820: Actively Exploited Windows AFD.sys Zero-Day Enables SYSTEM Privilege Escalation
ID: 8531a71f-66e4-556f-a325-152411a7c0ea
STIX ID: report--8531a71f-66e4-556f-a325-152411a7c0ea
Feed Name: SOC Prime Blog
Microsoft’s August 2026 updates patched CVE-2026-68820, a use-after-free in the Windows AFD.sys driver that permits local privilege escalation to SYSTEM; the flaw was exploited in the wild by the Lazarus group as part of Operation Dream Job to escalate an initial foothold (via malicious PDFs/trojanized software and the MISTPEN downloader) and deploy the FudModule kernel rootkit, so organizations should prioritize the August patches and hunt for post-compromise indicators and privilege-escalation activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
