CVE-2026-68820: The AFD.sys Zero-Day Microsoft Patched in August While It Was Already Being Used to Escalate to SYSTEM, and Why Attackers Chain It with FudModule to Blind Your EDR
# CVE-2026-68820: The AFD.sys Zero-Day Microsoft Patched in August While It Was Already Being Used to Escalate to SYSTEM, and Why Attackers Chain It with FudModule to Blind Your EDR
Microsoft's August 2026 Patch Tuesday addressed 421 CVEs, but one of them immediately stood out because it was being exploited in production before a patch existed. CVE-2026-68820 is a use-after-free vulnerability in the Ancillary Function Driver for WinSock (AFD.sys), the kernel-mode component that mediates socket operations between user-mode applications and the operating system's network stack. A locally authenticated attacker with low privileges can run a specially crafted application that triggers a race condition in the driver, and through that condition elevate their privileges to SYSTEM without requiring user interaction. What makes this vulnerability particularly urgent is not only its active exploitation — a zero-day without a patch is already serious by definition — but the pattern in which attackers are using it in real operations: chained with kernel-mode rootkits such as FudModule, it serves to disable the EDR tools that would defend against the rest of the attack. CVE-2026-68820 is, operationally, the key that opens the last door before the attacker does whatever they want with the machine.
This report explains the vulnerability from the code level, documents the usage pattern observed in real incidents, evaluates the impact on different Windows configurations, and delivers an operational guide so blue teams can prioritize patch deployment, detect exploitation attempts, and mitigate risk on systems where the patch is not immediately applicable.
What the Microsoft advisory actually says
CVE-2026-68820 is classified as use-after-free (CWE-416) in AFD.sys. Microsoft describes the flaw as the result of improper synchronization when multiple threads interact concurrently with socket-related state. Under specific race conditions, one code path frees a memory object while another continues to access it, creating a memory corruption condition that can be weaponized for privilege escalation.
The Ancillary Function Driver for WinSock operates in kernel mode. Its job is to mediate I/O Request Packets (IRPs) between Winsock clients in user mode and the kernel network stack. When an application opens a socket, sends data, receives data, or closes a connection, the calls go through AFD.sys before reaching the TCP/IP stack. This makes AFD.sys a critically important component of the operating system: any user-mode process that uses the network — and practically all do — interacts with this driver multiple times per second.
The vulnerability requires a local authenticated attacker. This means the attacker already has at least a foothold on the target machine — typically a standard user account, obtained via phishing, credential theft, or a previously compromised endpoint. From that position, the attacker can execute a specially crafted application that interacts with AFD.sys concurrently to trigger the race condition. Microsoft confirms that successful exploitation delivers full SYSTEM privileges without requiring user interaction.
Microsoft confirmed that the vulnerability was exploited as a zero-day before a patch was available. This confirmation arrived in the August Patch Tuesday advisory, not in a later update, which indicates that Microsoft's telemetry saw the exploitation in real operations against customers in its installed base. The exploitation likely involved using the vulnerability as the second or third step in longer attack chains — the attacker reaches the machine with low privileges, escalates to SYSTEM with CVE-2026-68820, and from SYSTEM disables defenses or installs persistence.
Why the FudModule pattern changes the equation
Analyses published by Securden, SOCRadar, and other security firms have documented a concerning pattern in incidents where CVE-2026-68820 appears. The pattern has three phases.
In the first phase, the attacker establishes an initial foothold. Typically this is a malicious macro in an Office document, a loader in an email attachment, or a payload served from a compromised site that exploits a browser or productivity application vulnerability. This first phase delivers to the attacker user-mode code execution with the privileges of the current user — a standard corporate user, without elevated permissions.
In the second phase, the attacker chains CVE-2026-68820. With the ability to execute arbitrary user-mode code, the attacker deploys an exploit specifically designed for the race condition in AFD.sys. The exploit typically involves multiple threads creating and closing sockets concurrently to maximize the probability that the race condition triggers. When the exploit succeeds, the attacker executes code in kernel mode with SYSTEM privileges. This delivers total control over the machine: the ability to read and write any file, install drivers, manipulate system processes, and modify Windows configuration at the kernel level.
In the third phase, the attacker deploys FudModule or an equivalent rootkit. FudModule is a kernel-mode rootkit designed specifically to target EDR tools. Its primary function is to "blind" the security products the endpoint is running — it manipulates the kernel so that the calls the EDR makes to the operating system return false information or are silently blocked. With the EDR effectively neutralized, the attacker has the freedom to complete their final objective: data theft, ransomware deployment, long-term persistence, or lateral movement to other systems on the network.
What makes this pattern particularly dangerous is the order. CVE-2026-68820 is not the final payload; it is the precondition for the final payload to be possible. The EDR tool the endpoint has configured — CrowdStrike, SentinelOne, Microsoft Defender for Endpoint, any other — may have detected the initial user-mode foothold. But once the attacker escalates to SYSTEM and disables the EDR, that detection stops mattering. The window between "the EDR detected the initial intrusion" and "the attacker disabled the EDR" can be minutes. If the response team does not act within those minutes, the intrusion becomes effectively invisible.
Why AFD.sys is a recurring target
CVE-2026-68820 is not the first time AFD.sys has appeared in Microsoft security advisories. The component's history includes significant vulnerabilities in recent Windows versions, and the reason is structural. AFD.sys has existed since the early days of Winsock and has been extended layer by layer to accommodate new functionality: support for IPv6, for high-speed sockets, for I/O completion ports, for Registered I/O (RIO), and for integration with the Windows Filtering Platform. Each extension adds complexity to the driver internal state management, and each point of concurrency between extensions is a candidate for race conditions.
Microsoft has invested in rewriting parts of the Windows network stack in recent versions, but AFD.sys remains, in essence, a three-decade-old driver that has been patched incrementally. The result is a component whose attack surface is disproportionately large for what it does, and where systematic auditing of race conditions requires specialized tools that most fuzzing processes cannot reach.
For blue teams, this means AFD.sys must be treated as a high-risk asset. Vulnerabilities in this driver are going to keep appearing, and each one has the potential to deliver full machine control to a local attacker. Defensive strategy must assume that the next CVE in AFD.sys will arrive, and that it will be exploited in real operations. That changes the conversation about compensating controls.
What blue teams need to do in the next 48 hours
The operational response to CVE-2026-68820 has five components.
**Patch with maximum priority.** The August 2026 patch closes the vulnerability for all supported versions of Windows. Deployment should follow reverse-risk order: first servers with sensitive data, then user endpoints with access to critical systems, then the rest of the installed base. In organizations using Windows Server Update Services or Intune, deployment can be significantly accelerated; in organizations with misconfigured WSUS or without MDM, manual deployment must be planned.
**Enable Credential Guard or LSA Protection on endpoints that do not yet have it.** Credential Guard uses virtualization to isolate credentials in a secure component of the operating system, so that even an attacker with SYSTEM privileges in the kernel cannot extract them. LSA Protection (RunAsPPL) is a lighter protection that prevents unsigned code from reading Local Security Authority memory. Neither of these prevents exploitation of CVE-2026-68820 directly, but both mitigate the attacker's final objective: stealing credentials that enable lateral movement.
**Limit who can execute arbitrary code on endpoints.** Apply AppLocker or Windows Defender Application Control (WDAC) with policies that limit binaries that can run from user-writable directories. If the attacker cannot execute the AFD.sys exploit from their DLL in `%APPDATA%`, the attack-chain pattern breaks in the second phase.
**Monitor AFD.sys-related events.** Configure alerts for massive socket creation in processes that normally do not use them. Configure alerts for patterns of multiple threads opening and closing sockets in short bursts. Configure alerts for loading of unsigned or invalidly signed drivers, which is the attacker's typical next step once they escalate to SYSTEM.
**Have an intrusion-response playbook with EDR compromise.** If the corporate endpoint runs an EDR, that EDR must have a robust "tamper protection" policy configured that requires user interaction or a specific token to disable. But even with active tamper protection, an attacker with SYSTEM in kernel can potentially disable it. The playbook must assume that scenario: what does the response team do if the EDR stops reporting from a specific endpoint? How long until that endpoint is treated as compromised and isolated from the network?
The specific problem of Windows 10 1607
SentinelOne explicitly documented that CVE-2026-68820 affects Windows 10 1607. This version, also known as Windows 10 Anniversary Update or Windows Server 2016, was originally released in 2016 and remains in extended support until October 2026. There is a significant installed base of Windows 10 1607 in industrial environments, in kiosk systems, in medical appliances, and in legacy systems that organizations have not migrated due to cost or operational risk.
For those organizations, the patch is available. The real decision is whether to deploy the patch on the normal cadence or to accelerate. The recommendation for Windows 10 1607 systems with sensitive data or with access to critical infrastructure is to accelerate deployment. For Windows 10 1607 systems in isolated or low-risk environments, the normal cadence is acceptable, but with active monitoring for indicators of compromise.
There is a second consideration. Windows 10 is on an end-of-support trajectory that has specific milestones for each edition. Organizations still running Windows 10 1607 in production should be executing, in parallel with the CVE-2026-68820 patch, a migration plan to Windows 10 LTSC, Windows 11, or some other supported platform. The number of high-severity vulnerabilities in legacy Windows 10 components is going to keep growing, and each monthly patch will feel operationally heavier.
The read for platform teams
CVE-2026-68820 is an uncomfortable reminder of something the security industry has internalized but that organizations keep paying for: the attack surface of a modern corporate endpoint is huge, and legacy drivers are one of the hardest points to defend. There is no EDR that can defend against a kernel exploit if the EDR itself is the target of the exploit. There is no antivirus that can block a payload whose first step is disabling the antivirus. The defense chain must assume it will fail at some point, and must have redundancies that limit blast radius when it does.
The three most important redundancies in this context are those that reduce the value of the attacker's final objective, not those that try to prevent the initial intrusion. Credential Guard reduces the value of compromising the endpoint for lateral movement. WDAC reduces the value of the endpoint as a platform to execute malicious code. Network isolation of critical endpoints reduces the value of the endpoint as a pivot to more sensitive systems. None of these measures prevents exploitation of CVE-2026-68820; all limit what the attacker can do after exploiting it.
That is the conversation blue teams need to have with asset management teams and with CISOs. The question is not "can we prevent the next AFD.sys use-after-free?"; we cannot. The question is "how expensive do we make it for the attacker to exploit it?". Each compensating control properly deployed is an increase in the attacker's cost of operation. If that cost exceeds the value of the objective, the attacker goes elsewhere. If not, we must keep raising the cost.
Conclusion
CVE-2026-68820 is a serious, actively exploited vulnerability that merits priority response. But beyond the specific incident, it is a useful case study on how attackers chain privilege-escalation vulnerabilities with malware that targets the defense. The patch is necessary; compensating controls are indispensable; the conversation about the endpoint threat model is what will determine whether the next similar vulnerability becomes an incident or an anecdote.
The clock is ticking, and this time it is not metaphorical.