Summary
- CVE-2026-68820 affects the Windows Ancillary Function Driver and can elevate an attacker with existing code execution to SYSTEM privileges.
- Check Point observed the zero-day in a Lazarus-linked Operation Dream Job campaign focused on defence, aerospace, and aviation targets, including Western Europe.
- Microsoft fixed the flaw on 11 August after disclosure by Check Point, turning endpoint patching into the immediate containment point for an already exploited attack chain.
A Windows zero-day used to gain SYSTEM privileges has been patched after researchers observed it in a campaign targeting defence, aerospace, and aviation organisations, including victims in Europe.
Microsoft fixed CVE-2026-68820 in its 11 August security updates. The vulnerability affects the Windows Ancillary Function Driver, or AFD.sys, a kernel component involved in networking. Successful exploitation allows an attacker who has already achieved code execution on a machine to elevate privileges to SYSTEM, giving malicious software substantially greater control of the host.
The active exploitation was uncovered by Check Point Research during its investigation of the long-running Operation Dream Job campaign. Check Point associates that activity with the North Korea-linked Lazarus group and said the latest wave has focused particularly on defence-sector organisations in Europe and India. That attribution is the researchers’ assessment rather than a separate government determination.
CVE-2026-68820 is therefore not an internet-facing remote-code-execution flaw that can independently compromise an untouched Windows machine. It is a second-stage vulnerability: the attacker first needs code running on the endpoint, then uses the kernel flaw to move from that foothold into a privileged context. In the observed campaign, Check Point said the exploit was used to deploy a new version of FudModule, a kernel-mode tool associated with Lazarus operations.
The surrounding attack chain gives the vulnerability more weight than its role as a local privilege escalation flaw might suggest. Researchers observed fraudulent recruitment approaches, modified PDF-viewing software, impersonation websites, and malicious documents being used to establish access. One campaign variant used a trojanised application called SecurityPDF, while another used DLL sideloading to execute malware from what appeared to be legitimate software.
Check Point also found compromised Roundcube and WordPress servers being used as relay infrastructure for attacker communications. At least one compromised organisation in Western Europe was subsequently used to support spear-phishing activity against further targets. The researchers said the legitimate company Enveil was impersonated by malicious sites in part of the operation, but found no indication that Enveil itself had been compromised.
The campaign illustrates the practical value of local privilege-escalation vulnerabilities to sophisticated intrusion operators. Initial execution is only one stage of an enterprise compromise. Moving into SYSTEM context can allow malware to interfere with endpoint protections, access protected resources, and establish a position from which later stages of an intrusion become harder to observe or contain.
That is particularly consequential in defence and aerospace environments, where sensitive engineering information, government relationships, intellectual property, and access to wider industrial supply chains can all sit behind tightly monitored endpoints. Attackers that can combine credible social engineering with a previously unknown kernel vulnerability gain a way to bridge the gap between an initial user-level foothold and deeper control of a device.
Check Point said it reported the issue to Microsoft on 28 July. Microsoft confirmed the bug on 31 July, assigned CVE-2026-68820 on 5 August, and released the fix on 11 August. The short disclosure-to-patch interval limits the period between vendor confirmation and public remediation, but exploitation had already been occurring since at least early July according to the researchers.
The result is a patching decision driven by observed attacker behaviour rather than a theoretical severity score. Organisations that operate Windows endpoints in defence, aerospace, aviation, and adjacent supply chains now have an exploited kernel vulnerability embedded in a documented intrusion chain, with European targets already represented in the campaign.



