CVE-2026-68820
Published Aug 11, 2026
Last updated 2 months ago
AI description
CVE-2026-68820 is identified as a "Use after free" vulnerability found within the Windows Ancillary Function Driver for WinSock. This flaw enables an authorized attacker to achieve local privilege escalation. The vulnerability was recognized as a zero-day exploit and was actively leveraged in attacks. Microsoft addressed CVE-2026-68820 as part of its August 2026 Patch Tuesday release.
- Description
- Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
- Source
- secure@microsoft.com
- NVD status
- Analyzed
- Products
- windows_10_1607, windows_10_1809, windows_10_21h2, windows_10_22h2, windows_11_23h2, windows_11_24h2, windows_11_25h2, windows_11_26h1, windows_server_2012, windows_server_2016, windows_server_2019, windows_server_2022, windows_server_2025
CVSS 3.1
- Type
- Secondary
- Base score
- 7
- Impact score
- 5.9
- Exploitability score
- 1
- Vector string
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
Data from CISA
- Vulnerability name
- Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
- Exploit added on
- Aug 11, 2026
- Exploit action due
- Aug 25, 2026
- Required action
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- secure@microsoft.com
- CWE-416
- Hype score
- Not currently trending
Active in-the-wild zero-day and privilege escalation attacks targeting the Windows kernel and core OS execution layer center on several key vulnerabilities added to CISA's Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-68820 (Windows Kernel Ancillary Function Driver
@reach2ratan
12 Sept 2026
840 Impressions
19 Retweets
23 Likes
7 Bookmarks
0 Replies
0 Quotes
Check Point Research just detailed how Lazarus Group exploited a Windows zero-day (CVE-2026-68820) in AFD.sys. They lured defense professionals with fake job offers on LinkedIn. https://t.co/ED8UCF4kxu
@jorgeCISO
2 Sept 2026
7 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
🚨 Patch Now | September 1, 2026 Bringing these critical vulnerabilities to your attention: 🔴 Citrix NetScaler ADC/Gateway(CVE-2026-8452, CVSS 8.8) 🟠 Microsoft Windows AFD.sys (CVE-2026-68820, CVSS 7.0) 🔴 PaperCut NG/MF (CVE-2026-81578 & CVE-2026-82078, CVSS 8.
@CERT_UG
1 Sept 2026
115 Impressions
1 Retweet
1 Like
0 Bookmarks
1 Reply
0 Quotes
Recent zero-days: WinSock AFD.sys (CVE-2026-68820) actively exploited, Defender (CVE-2026-69414) unpatched EoP. NatJack attacks hijack TCP/DNS. Data privacy/integrity severely impacted. (Aug 2026) #Cybersecurity #Vulnerabilities #News
@YourAnon_irc
1 Sept 2026
45 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2026-68820 | Windows AFD.sys (WinSock) | use-after-free EoP | CVSS 7.0 | ITW local LPE to SYSTEM. Lazarus used it in Operation Dream Job to drop FudModule. on CISA KEV. https://t.co/1Sa6SajI6W #CVE #Windows #ExploitDev
@_MrNiko
31 Aug 2026
138 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Patch Now | August 25, 2026 Bringing these vulnerabilities to your attention. Today is the CISA deadline for ShieldBreak (CVE-2026-68820). - Dahua cameras Vulnerability - Progress LoadMaster (CVE-2026-8037) https://t.co/fR71dypdSf | #CyberSafeUG #CERTUGCC https://t.co/QP
@CERT_UG
25 Aug 2026
65 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
【技術解説】afd.sysゼロデイ CVE-2026-68820(CISA適用期限8/25=明日) 8月Patch
@iss_kk_official
23 Aug 2026
46 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Lazarus Group Exploits Windows WinSock Zero-Day CVE-2026-68820 to Deploy Advanced FudModule Rootkit | Encrygma — AI Cyber Security Intelligence ⚠️ https://t.co/LhQnDO2YHT
@crygma
23 Aug 2026
72 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-68820 is actively exploited and affects the Windows AFD driver. • Privilege escalation • CISA KEV listed 👉 Partner with Digital Warfare today and discover why organizations trust us to identify vulnerable systems. Read more: https://t.co/IBFidsSC2f https://t.co/rn
@Digital_Warfare
23 Aug 2026
26 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
【実務者への注意喚起】パッチ公開から72時間 ― 「後で当てる」がもう通用しない現実 8月Patch Tuesdayは421件のCVE、うちWinSock(AFD)の使用後解放 CVE-2026-68820 がゼロデイ悪用中でSYSTEM昇格に利用。SAP Commerce
@iss_kk_official
23 Aug 2026
44 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
This week’s defense ticket: prove version + exposure status for Windows CVE-2026-68820, Cisco ASA/FTD CVE-2026-20349, and Zoom’s annotation fixes. Close with evidence and exception owners, not “in progress.”
@InfosecDotWatch
22 Aug 2026
33 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Still sorting through Patch Tuesday? A few vulnerabilities deserve a closer look. In his August Patch Tuesday coverage for Infosecurity Magazine, Phil Muncaster looks at some of the vulnerabilities that stood out this month. Mike Walters highlights CVE-2026-68820 as a priority
@Action1corp
18 Aug 2026
89 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Microsoft'un Ağustos Yaması Final Raporunda 421 Açık ve İki Ek Sıfır Gün Ortaya Çıktı Daha önce duyurduğumuz Microsoft Ağustos yamasının resmi final raporunda toplam açık sayısı 398'den 421'e yükseldi ve Lazarus'un istismar ettiği CVE-2026-68820'nin yanınd
@BTHaberler
17 Aug 2026
35 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
North Korea used servers vulnerable to a bug we found as C2 in its latest campaign targeting the defence, aerospace, and aviation sectors. Check Point's report last week: Lazarus exploited a Windows kernel zero-day, CVE-2026-68820 in afd.sys, since at least early July against ht
@FearsOff
17 Aug 2026
386 Impressions
3 Retweets
8 Likes
2 Bookmarks
1 Reply
0 Quotes
NOOR Threat Feed Brief Here is a summary of the CVEs in under 120 words, prioritized by real-world exploitation risk: **High-Risk:** 1. **CVE-2026-68820**: Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability (local privilege escalation, high
@noorchronicle
17 Aug 2026
5 Impressions
1 Retweet
1 Like
0 Bookmarks
0 Replies
0 Quotes
Microsoft just dropped patches for 421 CVEs 💀 And one of them was already being exploited as a zero-day. CVE-2026-68820 is a Windows kernel bug that can give attackers SYSTEM privileges. Patch Tuesday is getting scary af. https://t.co/4xHu5AVlc3
@r3fang
16 Aug 2026
1 Impression
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Microsoft’s August Patch Tuesday addressed over 400 vulnerabilities, including one actively exploited zero-day (CVE-2026-68820) in the Windows Ancillary Function Driver. Prioritize systems exposed to privilege escalation risks.
@Lumideezy
16 Aug 2026
90 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
【今月のMSアップデート解説】 8月のセキュリティ更新は今月も420件超と多め ・WinSock AFDの権限昇格(CVE-2026-68820)は悪用確認あり ・SharePoint等のRCEチェーン(CVE-2026-63520)も要注意 昨今、不正アクセスが増え
@shunyat1031
16 Aug 2026
79 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
【緊急】CVE-2026-68820 MicrosoftのWindows Ancillary Function Driver for WinSockに深刻な脆弱性|即時対応が必要 https://t.co/OGjk5HJYtK #IT #Security #cybersecurity
@Teeeda_worker
16 Aug 2026
26 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-68820: Windows WinSock (afd.sys) UAF Mitigation by UBITQUITY. This repository contains a conceptual patch demonstrating the mitigation for CVE-2026-68820, a critical Use-After-Free (UAF) vulnerability in the Windows Ancillary Function Driver for WinSock (afd.sys).
@ubitquity_io
15 Aug 2026
144 Impressions
2 Retweets
3 Likes
0 Bookmarks
0 Replies
0 Quotes
ShieldBreak apunta a CVE-2026-50656 y lo que deja claro es bastante incómodo: Microsoft Defender parcheado, máquina parcheada, y aun así terminás en SYSTEM. Y no es una rareza aislada. Lazarus ya viene usando CVE-2026-68820 para subir privilegios en Windows, con casos en Bra
@FedeJoelH
15 Aug 2026
34 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-of-the-Day: CVE-2026-68820 — Windows AFD.sys, local privilege escalation CVSS: 7.0 | EPSS: N/A (too new to be scored) A use-after-free in a core Windows kernel driver lets an attacker with an existing foothold win a race condition and escalate to SYSTEM. Exploited as
@YourDailyCVE
15 Aug 2026
13 Impressions
0 Retweets
1 Like
0 Bookmarks
1 Reply
0 Quotes
🚨 NUEVA CVE: CVE-2026-68820 — Windows WinSock AFD (Use-After-Free LPE) ⚠️ CVSS 7.0 (CRÍTICO) · KEV 11/08/2026 · explotación activa Afectados: Sistemas Windows com driver AFD.sys Use-after-free https://t.co/rkgrmP2emR
@Douglas01284182
13 Aug 2026
14 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 NOVA CVE: CVE-2026-68820 — Windows WinSock AFD (Use-After-Free LPE) ⚠️ CVSS 7.0 (CRÍTICO) · KEV 11/08/2026 · exploração ativa Afetados: Sistemas Windows com driver AFD.sys Use-after-free no W https://t.co/jmt6RHDBtT
@Douglas01284182
13 Aug 2026
16 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 NEW CVE: CVE-2026-68820 — Windows WinSock AFD (Use-After-Free LPE) ⚠️ CVSS 7.0 (CRITICAL) · KEV 11/08/2026 · active exploitation Affected: Sistemas Windows com driver AFD.sys Use-after-free n https://t.co/HS0KUGrIZY
@Douglas01284182
13 Aug 2026
15 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
"Microsoft patched CVE-2026-68820 as part of August Patch Tuesday, a high severity bug in the Windows Ancillary Function Driver for WinSock already exploited in the wild. The flaw affects Windows 10 1607 to 22H2, Windows 11 23H2 to 26H1, and Windows Server 2012 to 2025, scored ht
@GHHILL1911
13 Aug 2026
242 Impressions
1 Retweet
6 Likes
0 Bookmarks
1 Reply
0 Quotes
🚨 Last 24h is HOT — primary sources only CISA added 3 KEVs on 11 Aug (all actively exploited): • CVE-2026-20349 — Cisco ASA/FTD unauth SSL VPN DoS Official: https://t.co/InN3hhGaSD Fed deadline: 14 Aug. No workarounds. Hotfix now. • CVE-2026-68820 — Windows afd.sys L
@seoscottsdale
13 Aug 2026
223 Impressions
0 Retweets
0 Likes
0 Bookmarks
2 Replies
0 Quotes
Lazarus is burning a Windows zero-day (CVE-2026-68820) against defense firms while SharePoint (CVE-2026-55040) falls to public PoC exploitation. #CyberSecurity #BlueTeam #ZeroDay https://t.co/1Fsc4x2SHo
@itsalreadywhen
13 Aug 2026
8 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
1/4 🚨 Last 24h cyber snapshot is HOT CISA just dropped 3 KEVs (Aug 11): Cisco ASA/FTD DoS (CVE-2026-20349), Windows AFD.sys LPE (CVE-2026-68820), Metabase unauth SQLi (CVE-2026-72898). Lazarus already weaponizing the Windows zero-day vs defense firms.
@CipherWardenAI
13 Aug 2026
202 Impressions
1 Retweet
0 Likes
0 Bookmarks
2 Replies
1 Quote
North Korean 🇰🇵 Lazarus Group weaponized a Windows zero-day (CVE-2026-68820) in Operation Dream Job, hitting defense and aerospace professionals in France 🇫🇷, Germany 🇩🇪, Brazil 🇧🇷, and India 🇮🇳 with fake Lockheed Martin job offers. - CVE-2026-68820
@DFIR_Radar
13 Aug 2026
199 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
Microsoft's August 2026 Patch Tuesday closed 3 zero-days (400+ CVEs total): - CVE-2026-68820 — AFD.sys (WinSock) — actively exploited - CVE-2026-62832 — Windows User Profile Service — publicly disclosed - CVE-2026-72971 — Container Isolation FS Filter Driver — public
@tac0tech
13 Aug 2026
77 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Microsoft patched CVE-2026-68820 as part of August Patch Tuesday, a high severity bug in the Windows Ancillary Function Driver for WinSock already exploited in the wild. The flaw affects Windows 10 1607 to 22H2, Windows 11 23H2 to 26H1, and Windows Server 2012 to 2025, scored
@NeowinFeed
13 Aug 2026
934 Impressions
3 Retweets
0 Likes
1 Bookmark
0 Replies
0 Quotes
North Korea 🇰🇵's Lazarus group deployed a Windows kernel zero-day via a post-quantum encrypted channel against defense and aerospace firms in France 🇫🇷, Germany 🇩🇪, Brazil 🇧🇷, and India 🇮🇳, with a patch shipping August 11. - CVE-2026-68820 is a use-
@DFIR_Radar
12 Aug 2026
228 Impressions
0 Retweets
2 Likes
0 Bookmarks
2 Replies
0 Quotes
Active exploitation of VMware vCenter (CVE-2026-59310) and Cisco ASA/FTD (CVE-2026-20349), plus a Windows afd.sys zero-day (CVE-2026-68820) in this month's Patch Tuesday. #CyberSecurity #BlueTeam #ZeroDay https://t.co/8JN5RsqS06
@itsalreadywhen
12 Aug 2026
11 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
🛡️We added Cisco Secure Firewall vulnerability CVE-2026-20349, Microsoft Windows vulnerability CVE-2026-68820 & Metabase vulnerability CVE-2026-72898 to our KEV Catalog. Visit https://t.co/myxOwap1Tf & apply mitigations to protect your org from cyberattacks. #Cyberse
@CISACyber
12 Aug 2026
8537 Impressions
7 Retweets
18 Likes
2 Bookmarks
1 Reply
0 Quotes
Microsoft patches 400+ vulnerabilities, one zero-day under attack (CVE-2026-68820): Microsoft’s August 2026 Patch Tuesday delivered security fixes for 400+ vulnerabilities, including one that has been exploited in zero-day attacks (CVE-2026-68820) and… https://t.co/DBkKoaPWYg
@shah_sheikh
12 Aug 2026
62 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔥 CyberForge CVE of the Day #022 🚨 CVE-2026-68820 — An actively exploited Windows Ancillary Function Driver for WinSock (afd.sys) use-after-free allows a low-privileged local attacker to elevate privileges through kernel memory corruption. ⭐ Vendor: Microsoft ⭐ Comp
@lee1981b
12 Aug 2026
109 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔥 CyberForge CVE of the Day #022 🚨 CVE-2026-68820 — An actively exploited Windows Ancillary Function Driver for WinSock (afd.sys) use-after-free allows a low-privileged local attacker to elevate privileges through kernel memory corruption. ⭐ Vendor: Microsoft ⭐ Comp
@lee1981b
12 Aug 2026
3 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔥 CyberForge CVE of the Day #022 🚨 CVE-2026-68820 — An actively exploited Windows Ancillary Function Driver for WinSock (afd.sys) use-after-free allows a low-privileged local attacker to elevate privileges through kernel memory corruption. ⭐ Vendor: Microsoft ⭐ Comp
@lee1981b
12 Aug 2026
18 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Operation Dream Job #Lazarus exploited CVE-2026-68820, a zero-day vulnerability in the Microsoft AFD.sys driver, to deploy a new version of FudModule, Lazarus’ kernel-mode rootkit. https://t.co/A7xGb08NtE Lazarus also used CVE-2025-49113 to exploit vulnerable Roundcube
@blackorbird
12 Aug 2026
2126 Impressions
6 Retweets
19 Likes
5 Bookmarks
1 Reply
0 Quotes
北朝鮮系Lazarusが、偽の求人を使うOperation Dream Jobを再展開し、WindowsのゼロデイCVE-2026-68820を悪用して防衛・航空宇宙企業を侵害した。攻撃ではトロイ化PDFビューアや新型バックドア、カーネルルートキットも
@yousukezan
12 Aug 2026
2479 Impressions
0 Retweets
13 Likes
10 Bookmarks
0 Replies
0 Quotes
🚨 Microsoft August Patch Tuesday — 398+ CVEs, 3 Zero-Days CVE-2026-68820 — WinSock EoP (ACTIVE zero-day, Lazarus) CVE-2026-62878 — DNS Server RCE (9.8, wormable) CVE-2026-62893 — TFTP Server RCE (9.8, more likely) → https://t.co/vOC4TItXgB #cybersecurity #PatchTuesd
@ThreatAft
12 Aug 2026
84 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Microsoft’s August Patch Tuesday addresses multiple critical vulnerabilities. Prioritise actively exploited CVE-2026-68820, alongside publicly disclosed CVE-2026-62832 and CVE-2026-72971. Review, test and patch promptly: https://t.co/01elXNUXLy #PatchTuesday #MSSP #SOC
@FactoryInternet
11 Aug 2026
190 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 𝗛𝗼𝗿𝗶𝘇𝗼𝗻 𝗔𝗹𝗲𝗿𝘁 – 𝗔𝘂𝗴𝘂𝘀𝘁 𝟮𝟬𝟮𝟲 𝗣𝗮𝘁𝗰𝗵 𝗧𝘂𝗲𝘀𝗱𝗮𝘆 August Patch Tuesday is here, and we have 𝟯 𝗻𝗲𝘄 𝘇𝗲𝗿𝗼-𝗱𝗮𝘆𝘀 and 𝟲 vulnerabilities with a CVS
@horizon_secured
11 Aug 2026
314 Impressions
0 Retweets
4 Likes
1 Bookmark
0 Replies
0 Quotes
Microsoft's August Patch Tuesday fixed 400 flaws, including 3 Windows zero-days, all local privilege-escalation bugs needing no user interaction: • CVE-2026-68820: AFD.sys WinSock flaw, already exploited by Lazarus to deploy the FudModule rootkit • CVE-2026-62832: User Profi
@XavierRiveraX
11 Aug 2026
92 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
0-Day Used by Lazarus in #DreamJob Campaign Against Defense Sector: 💥LPE vulnerability in Microsoft’s Afd.sys driver (CVE-2026-68820) 🧰New tools, including #Troy backdoor 🌍Compromised Roundcube servers (CVE-2025-49113) as infrastructure Read More : https://t.co/GDI2Z
@_CPResearch_
11 Aug 2026
8491 Impressions
50 Retweets
172 Likes
69 Bookmarks
2 Replies
2 Quotes
0-Day Used by Lazarus in #DreamJob Campaign Against Defense Sector: 💥LPE vulnerability in Microsoft’s Afd.sys driver (#CVE-2026-68820) 🧰New tools, including #Troy backdoor 🌍Compromised Roundcube servers (CVE-2025-49113) as infrastructure Read More : https://t.co/GDI2
@_CPResearch_
11 Aug 2026
269 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
0-Day Used by Lazarus in #DreamJob Campaign Against Defense Sector: 💥LPE vulnerability in Microsoft’s Afd.sys driver (#CVE-2026-68820) 🧰New tools, including #Troy backdoor 🌍Compromised Roundcube servers (CVE-2025-49113) as infrastructure Read More : https://t.co/GDI2Z
@_CPResearch_
11 Aug 2026
265 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
0-Day Used by Lazarus in the #DreamJob Campaign Against Defense Sector: 💥LPE via a vulnerability in Microsoft’s Afd.sys driver (#CVE-2026-68820) 🧰New tools, including the #Troy backdoor 🌍Compromised Roundcube servers (CVE-2025-49113) as infrastructure https://t.co/GDI
@_CPResearch_
11 Aug 2026
381 Impressions
1 Retweet
5 Likes
1 Bookmark
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "14FF7EDA-F43B-4BB4-BC6C-7EFE15382EEB",
"versionEndExcluding": "10.0.14393.9418",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*",
"matchCriteriaId": "CB3EDBCC-9F4E-49F2-9701-67D2C1F7B47A",
"versionEndExcluding": "10.0.14393.9418",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "3B36E37E-C661-4F5B-BFAB-8DE7EA3BBF5A",
"versionEndExcluding": "10.0.17763.9115",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*",
"matchCriteriaId": "490C0819-7717-4869-B85C-2A218E7C50B2",
"versionEndExcluding": "10.0.17763.9115",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:*:*",
"matchCriteriaId": "B27B392C-BA96-4CAA-8368-64DB0C90F204",
"versionEndExcluding": "10.0.19044.7663",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:*:*",
"matchCriteriaId": "94D69542-4258-4423-9815-0191DE06A4E7",
"versionEndExcluding": "10.0.19045.7663",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:*:*",
"matchCriteriaId": "0821B99A-2DDC-4B1E-999A-76EC1D018CD5",
"versionEndExcluding": "10.0.22631.7517",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:*:*",
"matchCriteriaId": "3539AA11-7E3B-4EBC-9427-C2F58A6BA963",
"versionEndExcluding": "10.0.26100.9106",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:*:*",
"matchCriteriaId": "F25F821F-F56B-4150-80B7-9A6108FAA8BD",
"versionEndExcluding": "10.0.26200.9106",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:*:*",
"matchCriteriaId": "645B7F94-BBDA-41B1-825B-6103F2AC2FC9",
"versionEndExcluding": "10.0.28000.2704",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*",
"matchCriteriaId": "A7DF96F8-BA6A-4780-9CA3-F719B3F81074",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*",
"matchCriteriaId": "DB18C4CE-5917-401E-ACF7-2747084FD36E",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*",
"matchCriteriaId": "14EEFCD3-C815-4CBE-99AB-6AFB40EF2FE9",
"versionEndExcluding": "10.0.14393.9418",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*",
"matchCriteriaId": "7877A816-4EF3-4DA9-81F6-DF77056F329B",
"versionEndExcluding": "10.0.17763.9115",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*",
"matchCriteriaId": "8EBC7E47-4744-4802-B04C-869AA63985A5",
"versionEndExcluding": "10.0.20348.5440",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*",
"matchCriteriaId": "48C0EB1A-5EC0-4916-A812-08E16FEB040A",
"versionEndExcluding": "10.0.26100.33222",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]