Zero‑Day Privilege‑Escalation in Windows AFD.sys (CVE‑2026‑68820) Exploited by Lazarus Targeting Defense Firms
What It Is – A use‑after‑free flaw in the Windows Ancillary Function Driver for WinSock (AFD.sys) allows a locally‑authenticated attacker to trigger a race condition and gain SYSTEM privileges without user interaction.
Exploitability – Actively exploited in the wild since early July 2026; a proof‑of‑concept is embedded in the Lazarus “Operation Dream Job” campaign. Microsoft rated the vulnerability as high‑severity and issued a Patch Tuesday fix.
Affected Products – Microsoft Windows 10, Windows 11 (builds 26100 and 26200) and any Windows version that includes the vulnerable AFD.sys driver.
Why It Matters for Compliance & Audit Readiness
- SOC 2 control mapping (CC6.1 Change Management, CC6.2 Patch Management) must demonstrate timely remediation of critical OS flaws; a missed patch is a control gap.
- Continuous evidence collection (e.g., patch‑status dashboards, endpoint telemetry) provides audit‑ready proof that the organization is actively mitigating high‑risk vulnerabilities.
- Defense‑sector clients increasingly demand verifiable SOC 2 evidence that privileged‑access controls are enforced and that zero‑day exposures are promptly addressed.
Recommended Actions
- Deploy Microsoft’s July 2026 Patch Tuesday update across all Windows endpoints immediately.
- Verify patch compliance with automated inventory tools; capture screenshots or logs as audit evidence.
- Enable and monitor Windows Event ID 4688 (process creation) and Sysmon for anomalous “SYSTEM” privilege escalations.
- Map the remediation to SOC 2 CC6.1/CC6.2 controls and record the remediation workflow in your Trust Center for future audits.
- Review privileged‑access policies and enforce least‑privilege principles for local accounts.
Source: BleepingComputer – Lazarus hackers exploited Windows zero‑day to target defense firms