Windows 10 bug can let attackers gain admin control

Published August 11, 2026 CVE-2026-68820

A flaw in Windows 10 Version 1607 lets attackers with local access run commands as admin. Microsoft calls it an 'elevation of privilege' bug.

Severity
HighCVSS 3.1 · 7.0
Fix
Update availableFix recorded on Aug 26, 2026
Affected versions
10.0.14393.0 to before 10.0.14393.9418; 10.0.17763.0 to before 10.0.17763.9121; 10.0.19044.0 to before 10.0.19044.7663+17 more
Weakness
CWE-416Use After Free
Exploit likelihood
6.2% in 30 daysEPSS, higher than 93% of known flaws
Affects
Windows 10 Version 1607+18 more
Exploited
Yes, in the wildListed by CISA
Added to CISA list
Aug 11, 2026
Federal fix deadline
Aug 25, 2026

How it works

An attacker tricks the Windows network driver into using memory that was already freed, then crashes the system or runs commands as admin.

What to do

Check whether the installed Microsoft version is older than the fixed version in the vendor advisory or current release.

Update to Windows 10 Version 1703 or newer through Windows Update, then check your version in Settings > System > About.

Technical details

Affected software: Windows 10 Version 1607by Microsoft, Windows 10 Version 1809by Microsoft, Windows 10 Version 21H2by Microsoft, Windows 10 Version 22H2by Microsoft, Windows 11 version 23H2by Microsoft, Windows 11 Version 24H2by Microsoft, Windows 11 Version 25H2by Microsoft, Windows 11 version 26H1by Microsoft, Windows Server 2012by Microsoft, Windows Server 2012 (Server Core installation)by Microsoft, Windows Server 2012 R2by Microsoft, Windows Server 2012 R2 (Server Core installation)by Microsoft, Windows Server 2016by Microsoft, Windows Server 2016 (Server Core installation)by Microsoft, Windows Server 2019by Microsoft, Windows Server 2019 (Server Core installation)by Microsoft, Windows Server 2022by Microsoft, Windows Server 2025by Microsoft, Windows Server 2025 (Server Core installation)by Microsoft

Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.

Severity breakdown

  • Attack vector Local Needs local access to the machine
  • Attack complexity High Attack depends on conditions outside the attacker's control
  • Privileges required Low Attacker needs a basic user account
  • User interaction None No victim action needed
  • Scope Unchanged Impact stays within the same security authority
  • Confidentiality impact High Sensitive data can be exposed with serious impact
  • Integrity impact High Protected data can be changed with serious impact
  • Availability impact High The service can stop or suffer serious disruption
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H Open in FIRST.org calculator

References