Windows 10 bug can let attackers gain admin control
A flaw in Windows 10 Version 1607 lets attackers with local access run commands as admin. Microsoft calls it an 'elevation of privilege' bug.
- Severity
- HighCVSS 3.1 · 7.0
- Fix
- Update availableFix recorded on Aug 26, 2026
- Affected versions
- 10.0.14393.0 to before 10.0.14393.9418; 10.0.17763.0 to before 10.0.17763.9121; 10.0.19044.0 to before 10.0.19044.7663+17 more
- Weakness
- CWE-416Use After Free
- Exploit likelihood
- 6.2% in 30 daysEPSS, higher than 93% of known flaws
- Affects
- Windows 10 Version 1607+18 more
- Exploited
- Yes, in the wildListed by CISA
- Added to CISA list
- Aug 11, 2026
- Federal fix deadline
- Aug 25, 2026
How it works
An attacker tricks the Windows network driver into using memory that was already freed, then crashes the system or runs commands as admin.
What to do
Check whether the installed Microsoft version is older than the fixed version in the vendor advisory or current release.
Update to Windows 10 Version 1703 or newer through Windows Update, then check your version in Settings > System > About.
Technical details
Affected software: Windows 10 Version 1607by Microsoft, Windows 10 Version 1809by Microsoft, Windows 10 Version 21H2by Microsoft, Windows 10 Version 22H2by Microsoft, Windows 11 version 23H2by Microsoft, Windows 11 Version 24H2by Microsoft, Windows 11 Version 25H2by Microsoft, Windows 11 version 26H1by Microsoft, Windows Server 2012by Microsoft, Windows Server 2012 (Server Core installation)by Microsoft, Windows Server 2012 R2by Microsoft, Windows Server 2012 R2 (Server Core installation)by Microsoft, Windows Server 2016by Microsoft, Windows Server 2016 (Server Core installation)by Microsoft, Windows Server 2019by Microsoft, Windows Server 2019 (Server Core installation)by Microsoft, Windows Server 2022by Microsoft, Windows Server 2025by Microsoft, Windows Server 2025 (Server Core installation)by Microsoft
Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.
Severity breakdown
- Attack vector Local Needs local access to the machine
- Attack complexity High Attack depends on conditions outside the attacker's control
- Privileges required Low Attacker needs a basic user account
- User interaction None No victim action needed
- Scope Unchanged Impact stays within the same security authority
- Confidentiality impact High Sensitive data can be exposed with serious impact
- Integrity impact High Protected data can be changed with serious impact
- Availability impact High The service can stop or suffer serious disruption
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H Open in FIRST.org calculatorReferences
- msrc.microsoft.com · CVE-2026-68820 Patch Vendor Advisory
- cisa.gov · known-exploited-vulnerabilities-catalog US Government Resource