VYPR
Vypr IntelligenceAI-generatedAug 11, 2026· 17 CVEs

Windows Server 2003: 17 Vulnerabilities Disclosed, One Actively Exploited by Lazarus Group

Microsoft patched 17 vulnerabilities in Windows Server 2003 on August 11, 2026, including a zero-day exploited by Lazarus Group.

Key findings

  • 17 vulnerabilities in Windows Server 2003 disclosed on August 11, 2026, with a focus on privilege escalation and DoS flaws.
  • CVE-2026-68820, a use-after-free vulnerability, was actively exploited by the Lazarus Group in the 'Operation Dream Job' campaign.
  • Multiple 'use after free' and 'null pointer dereference' vulnerabilities were present across the batch.
  • CISA mandated federal agencies to patch CVE-2026-68820 within two weeks due to active exploitation.
  • All disclosed vulnerabilities were patched by Microsoft on August 11, 2026.

On August 11, 2026, Microsoft released a significant batch of 17 security advisories addressing vulnerabilities in Windows Server 2003. This coordinated disclosure event, occurring within a two-minute window, highlights ongoing security challenges for the aging operating system. The vulnerabilities span a range of severity, with several high-severity flaws allowing for privilege escalation and denial of service.

A notable theme within this batch is the prevalence of "use after free" vulnerabilities, which appeared in CVE-2026-68820, CVE-2026-61346, CVE-2026-59125, and CVE-2026-50472. These flaws, if exploited, could allow an authorized local attacker to elevate their privileges. Additionally, "null pointer dereference" vulnerabilities were present in CVE-2026-59138 and CVE-2026-59132, potentially leading to denial-of-service conditions over a network.

One vulnerability, CVE-2026-68820, a use-after-free flaw in the Windows Ancillary Function Driver for WinSock, was confirmed to be under active exploitation. News outlets reported that the North Korean threat actor Lazarus Group was leveraging this zero-day vulnerability as part of its "Operation Dream Job" campaign. This campaign targets professionals in the defense and aerospace sectors with fake job offers to deploy malware, including a new backdoor and a kernel-mode rootkit. CISA issued a directive for federal agencies to patch this specific vulnerability within two weeks due to its active exploitation.

The batch also included vulnerabilities related to the use of uninitialized resources, such as CVE-2026-59137 and CVE-2026-59136, which could lead to information disclosure. Other vulnerabilities involved weak authentication in the Windows Search Component (CVE-2026-59135), out-of-bounds reads in the Encrypting File System (CVE-2026-59128), and heap-based buffer overflows in the Windows Imaging Component (CVE-2026-54984).

Microsoft's advisories indicate that patches for all these vulnerabilities were released on August 11, 2026. Users are strongly advised to apply these updates promptly to mitigate the risks associated with these flaws, especially given the active exploitation of CVE-2026-68820. The sheer volume and severity of vulnerabilities disclosed in this single batch underscore the continued need for vigilance and timely patching, even for older operating systems like Windows Server 2003.

This coordinated disclosure event serves as a stark reminder of the persistent threats targeting widely used operating systems. The active exploitation of CVE-2026-68820 by a sophisticated threat actor like Lazarus Group highlights the critical importance of prompt patching and robust security practices. Organizations running Windows Server 2003 should prioritize applying the latest security updates to protect against privilege escalation, denial-of-service, and information disclosure attacks. The ongoing discovery of vulnerabilities in older systems also emphasizes the need for strategic migration plans to more modern and supported platforms.

AI-written article. Grounded in 17 CVE records listed below.
Windows Server 2003: 17 Vulnerabilities Disclosed, One Actively Exploited by Lazarus Group · VYPR