VYPR
Vypr IntelligenceAI-generatedAug 11, 2026· 25 CVEs

Microsoft Windows 11 24H2: 25 Vulnerabilities Patched, Including Actively Exploited Zero-Day

Microsoft addressed 25 Windows 11 24H2 vulnerabilities on August 11, 2026, including multiple privilege escalation flaws and one actively exploited zero-day.

Key findings

  • Microsoft patched 25 vulnerabilities in Windows 11 24H2 on August 11, 2026.
  • Multiple heap and stack buffer overflows in Windows Installer allow for local privilege escalation.
  • Several 'use after free' vulnerabilities across various Windows components also lead to privilege escalation.
  • CVE-2026-68820, a use-after-free flaw in Windows Ancillary Function Driver, is actively exploited by Lazarus Group.
  • The batch includes vulnerabilities affecting Windows Installer, Ancillary Function Driver, Key Guard, Storage Port Driver, and Win32K.

On August 11, 2026, Microsoft released a significant security update addressing 25 vulnerabilities in Windows 11 24H2. This batch of disclosures includes a mix of critical and high-severity flaws, with a particular focus on privilege escalation and buffer overflow vulnerabilities. The timely release, all within a two-minute window, highlights a coordinated effort to patch a wide range of potential security weaknesses.

A notable theme within this batch is the prevalence of heap-based and stack-based buffer overflows, primarily affecting the Windows Installer component. CVE-2026-70347, CVE-2026-70345, and CVE-2026-70344 all fall into this category, with descriptions indicating that an authorized attacker could exploit these flaws locally to elevate privileges. Similarly, CVE-2026-66799 and CVE-2026-65814 represent heap-based buffer overflows in the Windows Key Guard and Windows Storage Port Driver, respectively, also leading to local privilege escalation.

Another significant group of vulnerabilities involves "use after free" errors. CVE-2026-70307 and CVE-2026-68820, affecting the Windows Ancillary Function Driver for WinSock, and CVE-2026-65783, CVE-2026-65782, CVE-2026-65781, CVE-2026-65779, CVE-2026-65778, and CVE-2026-65776, impacting Windows Autopilot and Win32K respectively, all allow for local privilege escalation. The Desktop Window Manager is also affected by heap-based buffer overflows in CVE-2026-65787 and CVE-2026-65786, leading to similar privilege escalation outcomes.

The batch also includes vulnerabilities related to improper link resolution and access control. CVE-2026-70348, an improper link resolution flaw in Windows Management Services, allows for a local denial of service. CVE-2026-66804, an improper access control vulnerability in the Windows Cross Device Service, also permits local privilege escalation. Information disclosure vulnerabilities are present as well, with CVE-2026-65794 (Windows SMB Client) and CVE-2026-65784 (Windows NTFS) allowing unauthorized information disclosure under different conditions. Additionally, CVE-2026-65777, an inadequate encryption strength issue in Windows Active Directory, could allow an attacker to bypass a security feature. Finally, CVE-2026-65775, an uncontrolled resource consumption vulnerability in the Windows DHCP Client, enables an adjacent network attacker to deny service.

Notably, CVE-2026-68820, a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock, was identified as being actively exploited in the wild. News outlets reported that the North Korean threat actor Lazarus Group was leveraging this vulnerability as part of its "Operation Dream Job" campaign, targeting defense and aerospace companies. CISA added this CVE to its Known Exploited Vulnerabilities Catalog, mandating federal agencies to patch it.

Microsoft's August 2026 Patch Tuesday addressed these 25 vulnerabilities, with fixes for CVE-2026-68820 being a priority due to active exploitation. Users are strongly advised to apply all available updates to protect against these diverse threats, particularly those related to privilege escalation and potential denial of service. The sheer volume and variety of vulnerabilities underscore the ongoing need for diligent security practices and prompt patching.

AI-written article. Grounded in 25 CVE records listed below.