Microsoft Fixes 421 Bugs as North Korea Exploits Windows WinSock Zero-Day

by priyanka.patel tech editor
Microsoft Fixes 421 Bugs as North Korea Exploits Windows WinSock Zero-Day

Microsoft issued its August 2026 Patch Tuesday update on August 11, fixing 421 vulnerabilities across its product ecosystem. The release is highlighted by an actively exploited zero-day privilege-escalation flaw in the Windows Ancillary Function Driver for WinSock, which state-sponsored hackers have already deployed in targeted campaigns.

Microsoft released its monthly security updates on August 11, addressing a sweeping total of 421 vulnerabilities. While down from the figures seen earlier in the summer, the volume remains significantly elevated compared to historical averages, driven in large part by AI-assisted vulnerability disclosures and fixes.

The standout threat in this month’s advisory is a high-severity flaw that attackers weaponized before a fix became available. Security vendors have urged immediate deployment as defenders confront a complex mix of elevation-of-privilege defects and remote code execution vulnerabilities.

Active Exploitation of the WinSock Driver Zero-Day

The central danger in the August update is tracked as CVE-2026-68820, a use-after-free memory vulnerability residing in afd.sys, the Ancillary Function Driver for WinSock and a core kernel-side component of Windows networking. The defect carries a CVSS score of 7.0 and allows an authenticated local attacker to trigger a race condition, elevating their access to full system privileges.

Microsoft Fixes 421 Bugs as North Korea Exploits Windows WinSock Zero-Day
Photo: forbes.com

According to threat intelligence analysts, North Korea’s Lazarus Group actively exploited this defect as a zero-day as early as the beginning of June. Theregister observed the attackers leveraging the vulnerability during Operation Dream Job, a long-running espionage campaign targeting the defense sector in Europe and India by impersonating organizations like Lockheed Martin and privacy-tech firm Enveil.

During these intrusions, attackers distributed malicious PDFs that executed a previously unseen backdoor named Troy while exploiting CVE-2026-68820 to deploy a fresh version of FudModule, the group’s kernel-mode rootkit.

“Because the driver is present on most Windows systems, it gives attackers a broad target and a potential path from limited access to full control.”

Amol Sarwate, Cohesity

Pairing Flaws Create Full System Compromise Risk

Beyond the actively exploited driver bug, security experts highlighted a second vulnerability that demands urgent patching because of how easily it pairs with initial footholds. Tracked as CVE-2026-62832, this improper link resolution bug in the Windows User Profile Service carries a CVSS score of 7.8 and was publicly known prior to the August update.

Microsoft Fixes 421 Bugs as North Korea Exploits Windows WinSock Zero-Day
Photo: securityweek.com

The advisory notes that an authenticated attacker with credentials for a local account can run a specially crafted application to load another user’s registry hive, gaining administrator privileges without requiring user interaction.

“That makes this pair the clear priority for defenders this month.”

Amol Sarwate, Cohesity

Unauthenticated Remote Code Execution Threats

Network administrators also face a daunting roster of critical remote code execution flaws that require zero user interaction and demand no prior credentials. Four distinct server-side vulnerabilities each carry CVSS severity scores of 9.8 and sit immediately behind the exploited driver bug in terms of priority.

Microsoft Fixes 421 Bugs as North Korea Exploits Windows WinSock Zero-Day
Photo: The Hacker News

The zero-day initiative flagged CVE-2026-62878, a remote code execution vulnerability in Windows DNS Server, characterizing the near-maximum severity flaw as a good ol’ fashioned stack-based buffer overflow that is technically wormable.

The remaining high-risk network flaws include CVE-2026-62893 in Windows Deployment Services, reachable via TFTP handling; CVE-2026-62815 affecting Microsoft’s implementation of the QUIC transport protocol; and CVE-2026-59124 in the High Performance Computing Pack. While the HPC component carries a 9.8 score, Microsoft rates it as Important rather than Critical because the pack is not installed by default on standard configurations.

The AI-Driven Volume Trend Continues

The 421 patches issued in August follow an even larger deluge in July, marking the second consecutive month of exceptionally high vulnerability counts. Industry experts point out that automated scanning tools and artificial intelligence are fundamentally altering the software security landscape.

🛡️ Microsoft Patches 77 Bugs Including Critical Office RCE Flaws 🛡️

Microsoft has explicitly warned corporate customers to expect elevated patch volumes moving forward as the company expands its use of AI tools to identify vulnerabilities in its products.

Industry voices emphasize that vulnerability management programs must rely on precise risk-based prioritization rather than raw CVE counts.

Distribution Breakdown and Enterprise Guidance

The August security portfolio spans a wide array of enterprise software lines.

  • 236 vulnerabilities affecting Windows operating systems
  • 98 flaws located within Office applications
  • 98 flaws located within Office 2016
  • 30 issues inside SharePoint Server
  • 26 developer tools defects
  • 17 Azure cloud environment patches
  • 7 Exchange Server security holes
  • 1 Defender defect alongside other specialized components

Security specialists urge administrators to verify service reachability and apply cumulative updates immediately to disrupt active state-sponsored targeting.

You may also like