# Windows Driver Zero-Day Tied to Lazarus Leads Microsoft's 398-Flaw August Patch Tuesday


## The Threat


A use-after-free in afd.sys — the Ancillary Function Driver for WinSock, the kernel component that sits underneath virtually every Windows network socket operation — is being actively exploited in the wild. CVE-2026-68820 allows an attacker who already has code running on a target machine to escalate privileges to SYSTEM by triggering a race condition in the driver. Check Point Research has attributed exploitation to North Korea's Lazarus Group, operating under the banner of Operation Dream Job, the long-running campaign that uses fake technical job offers to compromise engineers at defense contractors, crypto firms, and critical infrastructure targets.


That attribution changes the calculus significantly. Lazarus doesn't burn zero-days on opportunistic spam runs. When they use one, they're targeting specific organizations with specific goals — typically espionage or financial theft — and they've had the bug for some time before it surfaces publicly. The practical implication: any organization that fits Lazarus's typical targeting profile (aerospace, defense, financial services, blockchain) should treat this patch as genuinely urgent rather than "next maintenance window" urgent.


The zero-day shares August's release with four unauthenticated remote code execution flaws, each carrying a 9.8 CVSS score, that affect Windows DNS Server, Windows Deployment Services, Microsoft QUIC, and HPC Pack. None of those four is currently under active exploitation, but three require no account, no credentials, and no user interaction — a server left reachable and unpatched is the entire attack surface. August also completes a two-part SharePoint fix whose first half shipped in July, closing an exploit chain that lets an unauthenticated attacker reach remote code execution against on-premises SharePoint farms.


## Severity and Impact


| CVE | CVSS Score | Type | Component | Attack Complexity | Auth Required | Exploited |

|-----|-----------|------|-----------|-------------------|---------------|-----------|

| CVE-2026-68820 | 7.0 | Privilege Escalation | afd.sys (WinSock driver) | High (race condition) | Local | Yes — actively |

| CVE-2026-62878 | 9.8 | Remote Code Execution | Windows DNS Server | Low | None | No |

| CVE-2026-62893 | 9.8 | Remote Code Execution | Windows Deployment Services | Low | None | No |

| CVE-2026-62815 | 9.8 | Remote Code Execution | Microsoft QUIC | Low | None | No |

| CVE-2026-59124 | 9.8 | Remote Code Execution | HPC Pack | Low | None | No |

| CVE-2026-55040 | 9.1 | Authentication Bypass | SharePoint Server | Low | None | No |


Release totals (per Zero Day Initiative): 398 new CVEs, 62 rated Critical.


## Affected Products


CVE-2026-68820 — afd.sys privilege escalation

  • All supported Windows client versions (Windows 10, Windows 11)
  • All supported Windows Server versions

  • CVE-2026-62878 — Windows DNS Server RCE

  • Windows Server with DNS Server role installed

  • CVE-2026-62893 — Windows Deployment Services RCE

  • Windows Server with WDS role installed

  • CVE-2026-62815 — Microsoft QUIC RCE

  • Windows systems running QUIC protocol stack (client and server)

  • CVE-2026-59124 — HPC Pack RCE

  • Systems with Microsoft HPC Pack installed (not a default component)

  • SharePoint chain (CVE-2026-55040 + August's companion RCE)

  • On-premises SharePoint Server deployments that have not applied both July and August cumulative updates

  • ## Mitigations


    Immediate priority — patch in this order:


    1. CVE-2026-68820 (afd.sys zero-day) — Apply the August 2026 Windows cumulative update across all endpoints and servers without waiting for a maintenance window. Active Lazarus exploitation means the threat is present now. Organizations cannot add network controls that prevent a local privilege escalation; the patch is the only fix.


    2. CVE-2026-62878 (DNS Server RCE) — Patch Windows DNS servers immediately. ZDI has characterized the technical conditions as wormable. If patching cannot happen within 24 hours, consider whether external DNS resolution can be temporarily routed through a hardened resolver while internal DNS infrastructure is updated.


    3. CVE-2026-62893, CVE-2026-62815 (WDS and QUIC RCE) — Patch Windows Deployment Services hosts and systems running QUIC. If WDS is not actively needed, disable the service until the patch is applied. QUIC is harder to isolate via firewall rules given its role in modern HTTP/3 traffic.


    4. SharePoint on-premises farms — Both the July update (CVE-2026-55040, authentication bypass) and the August update (RCE) must be installed. Either update alone leaves the farm exploitable. Rapid7 reported this chain to Microsoft on May 18, giving sophisticated attackers over two months to analyze the disclosure window.


    5. CVE-2026-59124 (HPC Pack) — Lower priority due to non-default deployment, but Microsoft rates exploitation as "more likely." Inventory whether HPC Pack is present in your environment before deprioritizing.


    General guidance:

  • Audit service exposure: none of the four 9.8 RCEs are exploitable unless the vulnerable service is reachable on the network. Service inventory and firewall rules reduce attack surface immediately, independent of patching timeline.
  • Segment servers running DNS, WDS, and QUIC from untrusted network segments where operationally feasible.
  • Organizations in Lazarus-targeted verticals (defense, crypto, critical infrastructure) should review endpoint detection telemetry for signs of privilege escalation attempts against afd.sys reaching back 60–90 days.

  • ## References


  • [Microsoft Security Update Guide — August 2026](https://msrc.microsoft.com/update-guide/)
  • [Zero Day Initiative August 2026 Patch Tuesday Analysis](https://www.zerodayinitiative.com/blog/)
  • [Check Point Research — Operation Dream Job](https://research.checkpoint.com/)
  • [Rapid7 Labs — SharePoint Chain Advisory](https://www.rapid7.com/blog/)

  • ---


    ## HackWire Analysis


    The Lazarus attribution on CVE-2026-68820 is the detail that demands attention, and not just because of the name recognition. Lazarus has been running Operation Dream Job since at least 2020, and the campaign has a documented pattern: identify high-value individuals at targeted organizations, approach them with convincing fake recruitment offers, walk them through a "technical assessment" that delivers malware, then spend months quietly inside the network before doing anything visible. A local privilege escalation zero-day fits precisely into that playbook — it's the tool you use after initial access, to get from a compromised user account to SYSTEM before defenders notice.


    The CVSS score of 7.0 will mislead some patch prioritization frameworks into queuing this below the four 9.8 server RCEs. That's a mistake. CVSS measures theoretical severity, not real-world urgency. An actively exploited local EoP in a known nation-state campaign beats an unpatched unauthenticated RCE that nobody has hit yet, every time. Prioritization tools that don't factor in exploitation status and threat actor profile will get this ranking wrong.


    The DNS Server "wormable" label from ZDI deserves scrutiny. ZDI is describing a technical characteristic — no authentication, no interaction, network-reachable — not confirming an existing worm. But the historical record on wormable Windows DNS bugs (think MS09-008, think the 2020 SIGRed disclosure) is not comforting. DNS servers sit at the edge of most enterprise networks, they're often treated as low-maintenance appliances, and they're almost never segmented away from internal clients. If exploitation materializes, propagation speed could be significant.


    For defenders: the SharePoint two-parter is a quiet operational trap. Organizations that patched July's authentication bypass and assumed the job was done are still exposed. Confirm both updates are installed before closing that ticket.


    — HackWire Editorial


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)