VYPR
Vypr IntelligenceAI-generatedAug 11, 2026· 17 CVEs

Windows 11 24H2: 17 Vulnerabilities Patched, One Actively Exploited by Lazarus Group

Microsoft patched 17 Windows 11 24H2 vulnerabilities on August 11, 2026, including CVE-2026-68820, actively exploited by the Lazarus Group.

Key findings

  • CVE-2026-68820, a Windows zero-day, is actively exploited by the Lazarus Group in Operation Dream Job.
  • 17 vulnerabilities disclosed on August 11, 2026, affecting Windows 11 24H2.
  • Multiple privilege escalation flaws patched, including use-after-free and race condition vulnerabilities.
  • Information disclosure and denial-of-service vulnerabilities also addressed in the batch.
  • CISA mandates urgent patching for federal agencies due to active exploitation of CVE-2026-68820.

On August 11, 2026, Microsoft released a significant security update addressing 17 vulnerabilities in Windows 11 24H2. The batch, disclosed simultaneously, includes a mix of high and medium severity flaws, with a particular focus on elevation of privilege and information disclosure vulnerabilities. Notably, one of these vulnerabilities, CVE-2026-68820, was confirmed to be under active exploitation by the Lazarus Group as part of their Operation Dream Job campaign, targeting defense and aerospace sectors with fake job offers.

The disclosed vulnerabilities span several key Windows components. Several "use after free" flaws were patched, including CVE-2026-68820 in the Windows Ancillary Function Driver for WinSock, CVE-2026-61346 in the Windows Graphics Kernel, CVE-2026-59125 in the Virtual Hard Disk (VHD) Miniport Driver, and CVE-2026-50472 in Windows LUAFV, all of which could allow local attackers to elevate privileges. Additionally, a race condition in the Windows Event Logging Service (CVE-2026-59126) and the Windows Telephony Service (CVE-2026-59122) also presented elevation of privilege risks.

Information disclosure vulnerabilities were also prevalent. CVE-2026-59137 in the Windows Event Logging Service and CVE-2026-59136 in Microsoft COM for Windows, both stemming from the use of uninitialized resources, allow local attackers to disclose information. Similarly, CVE-2026-59135 in the Windows Search Component and CVE-2026-59128 in the Windows Encrypting File System (EFS) present information disclosure risks due to weak authentication and out-of-bounds reads, respectively.

Denial-of-service vulnerabilities include CVE-2026-59138, a null pointer dereference in the Microsoft Remote Registry Service, and CVE-2026-59132, a null pointer dereference in Windows TCP/IP. CVE-2026-54113, an allocation of resources without limits or throttling in the Windows Kernel, also poses a denial-of-service risk. A critical vulnerability, CVE-2026-56179, in Windows Network Address Translation (NAT), allows unauthorized adjacent network attackers to perform spoofing. Finally, CVE-2026-54984, a heap-based buffer overflow in the Windows Imaging Component, could allow local attackers to execute code.

The active exploitation of CVE-2026-68820 by the Lazarus Group, as detailed by Check Point Research and reported by multiple news outlets, highlights the immediate threat posed by this batch. This vulnerability, a use-after-free flaw in AFD.sys, allowed attackers to gain SYSTEM privileges and deploy a rootkit. The campaign, Operation Dream Job, leverages social engineering tactics, with attackers posing as recruiters to lure targets in the defense and aerospace industries. CISA has issued directives for federal agencies to patch this vulnerability promptly.

Microsoft's August Patch Tuesday addressed these 17 vulnerabilities, along with hundreds of others, in a massive release aimed at securing Windows 11 24H2 and other products. Users are strongly advised to apply these updates to mitigate the risks associated with these flaws, particularly the actively exploited CVE-2026-68820. The simultaneous disclosure and active exploitation underscore the importance of timely patching and vigilance against sophisticated threat actors like Lazarus.

This batch of vulnerabilities serves as a stark reminder of the ongoing threats facing Windows users. The diverse range of flaws, from privilege escalation to information disclosure and denial of service, necessitates a comprehensive approach to security. The active exploitation of CVE-2026-68820 by a known threat actor emphasizes the critical need for prompt patching and robust security practices to defend against targeted attacks.

Key findings from this disclosure include the active exploitation of CVE-2026-68820 by the Lazarus Group as part of Operation Dream Job. The batch includes multiple privilege escalation vulnerabilities, primarily due to use-after-free and race condition flaws. Several information disclosure vulnerabilities were also patched, affecting components like the Windows Search Component and COM for Windows. The simultaneous disclosure of these 17 vulnerabilities on August 11, 2026, highlights a coordinated patching effort by Microsoft. The vulnerabilities affect Windows 11 24H2 and potentially other Windows versions. CVE-2026-50472, CVE-2026-54113, CVE-2026-54984, CVE-2026-56179, CVE-2026-59122, CVE-2026-59125, CVE-2026-59126, CVE-2026-59128, CVE-2026-59130, CVE-2026-59131, CVE-2026-59132, CVE-2026-59135, CVE-2026-59136, CVE-2026-59137, CVE-2026-59138, CVE-2026-61346, CVE-2026-68820

AI-written article. Grounded in 17 CVE records listed below.