VYPR
Vypr IntelligenceAI-generatedAug 11, 2026· 25 CVEs

Microsoft Windows Server 2012: 25 Vulnerabilities Disclosed, Zero-Day Exploited

Microsoft disclosed 25 vulnerabilities for Windows Server 2012, including an actively exploited zero-day (CVE-2026-68820) used by Lazarus Group.

Key findings

  • 25 vulnerabilities disclosed together for Windows Server 2012 on August 11, 2026.
  • CVE-2026-68820, a zero-day, actively exploited by Lazarus Group for privilege escalation.
  • Multiple heap-based buffer overflows and use-after-free flaws leading to privilege escalation and RCE.
  • Critical vulnerabilities include CVE-2026-62893 and CVE-2026-65791.
  • All vulnerabilities patched in Microsoft's August 2026 Patch Tuesday release.

On August 11, 2026, Microsoft disclosed a significant batch of 25 vulnerabilities affecting Windows Server 2012, with a critical zero-day vulnerability being actively exploited in the wild. This coordinated disclosure event, spanning just minutes, highlights a range of security weaknesses, primarily focusing on privilege escalation and remote code execution. The vulnerabilities were patched in Microsoft's August 2026 Patch Tuesday release.

A central theme among these vulnerabilities is the exploitation of memory corruption flaws, including heap-based buffer overflows and use-after-free errors. These types of vulnerabilities often allow attackers to gain control over system processes, leading to privilege escalation or remote code execution.

Specifically, CVE-2026-68820, a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock (AFD.sys), was identified as a zero-day being actively exploited. This flaw allows an authorized local attacker to elevate privileges to SYSTEM. This vulnerability was part of a broader campaign, Operation Dream Job, orchestrated by the Lazarus Group, a North Korean threat actor. The group targeted defense and aerospace companies by posing as recruiters and exploiting this zero-day to deploy a backdoor. CISA has added CVE-2026-68820 to its Known Exploited Vulnerabilities Catalog, mandating federal agencies to patch it within two weeks.

Other notable vulnerabilities include multiple heap-based buffer overflows in the Windows Installer (CVE-2026-70347, CVE-2026-70345) and Windows iSCSI Target Service (CVE-2026-65796, CVE-2026-65679, CVE-2026-65791), which allow for local privilege escalation or remote code execution. Use-after-free vulnerabilities in the Windows Ancillary Function Driver for WinSock (CVE-2026-68820, CVE-2026-68819) and Windows Win32K (CVE-2026-65775, CVE-2026-62885) also contribute to the risk of privilege escalation. Additionally, several out-of-bounds read vulnerabilities in components like Windows Network File System (CVE-2026-68819), Windows SMB Client (CVE-2026-65794), Windows NTFS (CVE-2026-65784, CVE-2026-62887, CVE-2026-62880), and Windows GDI (CVE-2026-65662) were disclosed, primarily leading to information disclosure.

The batch also includes critical vulnerabilities such as CVE-2026-62893, a use-after-free flaw in Windows Deployment Services, and CVE-2026-65791, a heap-based buffer overflow in the Windows iSCSI Target Service, both allowing for remote code execution. CVE-2026-62889, a double free in the Windows Secure Socket Tunneling Protocol (SSTP), also presents a remote code execution risk.

Microsoft addressed all these vulnerabilities in its August 2026 Patch Tuesday update. Users of Windows Server 2012 and other affected Windows versions are strongly advised to apply these patches immediately to mitigate the risk of exploitation, especially given the active exploitation of CVE-2026-68820 by sophisticated threat actors like Lazarus Group. The sheer volume and severity of these vulnerabilities underscore the ongoing need for diligent patch management and security monitoring.

The coordinated disclosure of these 25 vulnerabilities on August 11, 2026, presents a significant security challenge for Windows Server 2012 administrators. The prevalence of privilege escalation flaws, coupled with the active exploitation of a zero-day by a known threat actor, necessitates immediate attention. Organizations should prioritize patching, particularly for CVE-2026-68820, and remain vigilant against targeted attacks.

Key vulnerabilities include:

  • Heap-based buffer overflows in Windows Installer and iSCSI Target Service.
  • Use-after-free vulnerabilities in Windows Ancillary Function Driver for WinSock and Win32K.
  • Out-of-bounds read vulnerabilities in Network File System, SMB Client, NTFS, and GDI.
  • A critical use-after-free in Windows Deployment Services.

The active exploitation of CVE-2026-68820 by the Lazarus Group highlights the immediate threat posed by this batch of vulnerabilities. The campaign, Operation Dream Job, targeted defense and aerospace sectors with fake job offers, leveraging the zero-day to gain SYSTEM privileges.

Microsoft's August 2026 Patch Tuesday release addresses all 25 disclosed vulnerabilities. Prompt application of these security updates is crucial for all affected Windows Server 2012 systems.

This coordinated disclosure event serves as a stark reminder of the persistent threats facing Windows environments and the importance of timely security patching to defend against sophisticated attacks.

CVE-2026-70347, CVE-2026-70345, CVE-2026-70344, CVE-2026-70307, CVE-2026-68820, CVE-2026-68819, CVE-2026-66799, CVE-2026-65814, CVE-2026-65796, CVE-2026-65794, CVE-2026-65791, CVE-2026-65790, CVE-2026-65787, CVE-2026-65784, CVE-2026-65775, CVE-2026-65679, CVE-2026-65671, CVE-2026-65662, CVE-2026-62908, CVE-2026-62893, CVE-2026-62890, CVE-2026-62889, CVE-2026-62887, CVE-2026-62885, CVE-2026-62880

AI-written article. Grounded in 25 CVE records listed below.