VYPR
Vypr IntelligenceAI-generatedAug 11, 2026· 13 CVEs

Windows Server 2012: 13 Vulnerabilities Patched, One Actively Exploited by Lazarus Group

Microsoft addressed 13 Windows Server 2012 vulnerabilities on August 11, 2026, including a zero-day exploited by Lazarus Group for privilege escalation.

Key findings

  • Microsoft patched 13 vulnerabilities in Windows Server 2012 on August 11, 2026, including one actively exploited zero-day.
  • CVE-2026-68820, a use-after-free flaw in WinSock driver, was exploited by Lazarus Group in Operation Dream Job targeting defense and aerospace sectors.
  • Several vulnerabilities allow for local privilege escalation, including CVE-2026-68820, CVE-2026-50472, CVE-2026-54984, and CVE-2026-50472.
  • Denial of service and information disclosure vulnerabilities were also part of the batch, affecting components like TCP/IP and Event Logging Service.
  • The batch includes high-severity flaws like CVE-2026-68820 (7.0), CVE-2026-59132 (7.5), CVE-2026-54984 (7.8), and CVE-2026-54113 (7.5).

Microsoft released a significant security update on August 11, 2026, addressing a batch of 13 vulnerabilities affecting Windows Server 2012. The disclosures, all published on the same day, range in severity from medium to high, with a notable focus on privilege escalation and information disclosure flaws. The most critical of these, CVE-2026-68820, a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock, was confirmed to be under active exploitation by the Lazarus Group as part of the "Operation Dream Job" campaign. This campaign targets defense and aerospace professionals with fake job offers, aiming to steal sensitive data and deploy malware.

Several vulnerabilities center on privilege escalation, allowing local attackers to gain higher system access. CVE-2026-68820, rated High with a CVSS score of 7.0, enables an authorized attacker to elevate privileges locally through a use-after-free flaw in the WinSock driver. Similarly, CVE-2026-50472, a High-severity heap-based buffer overflow in Windows LUAFV, also allows for local privilege escalation. Another High-severity vulnerability, CVE-2026-54984, a heap-based buffer overflow in the Windows Imaging Component, could permit an unauthorized attacker to execute code locally. CVE-2026-68820, in particular, has garnered significant attention due to its exploitation in the wild by the Lazarus Group, a state-sponsored threat actor linked to North Korea. This vulnerability was used to deploy a kernel-mode rootkit and a new backdoor, targeting organizations in the defense and aerospace sectors across Europe and India.

Other vulnerabilities disclosed in this batch focus on denial of service and information disclosure. CVE-2026-59132, a High-severity null pointer dereference in Windows TCP/IP, allows an unauthorized attacker to deny service over a network. Medium-severity flaws like CVE-2026-59137 (Windows Event Logging Service) and CVE-2026-59136 (Microsoft COM for Windows) involve the use of uninitialized resources, potentially leading to local information disclosure. CVE-2026-59128, an out-of-bounds read in the Windows Encrypting File System (EFS), also presents an information disclosure risk. Additionally, CVE-2026-59135, a weak authentication vulnerability in the Windows Search Component, could allow an attacker to disclose information locally. CVE-2026-59131 and CVE-2026-59130, both rated Medium, also involve local information disclosure.

Microsoft's August Patch Tuesday addressed these vulnerabilities, with CVE-2026-68820 being the sole flaw confirmed to be under active exploitation. The company's advisories indicate that patches are available for all disclosed vulnerabilities. Users are strongly advised to apply these updates promptly to mitigate the risks associated with privilege escalation, denial of service, and information disclosure. The active exploitation of CVE-2026-68820 by a sophisticated threat actor like Lazarus Group underscores the urgency of patching, especially for organizations in sensitive sectors.

The coordinated disclosure of these 13 vulnerabilities highlights the ongoing efforts by security researchers and vendors to identify and remediate security weaknesses in widely used operating systems. While the batch includes a mix of severity levels, the presence of an actively exploited zero-day, CVE-2026-68820, alongside other privilege escalation and denial-of-service flaws, presents a substantial risk to Windows Server 2012 environments. Users should prioritize the application of Microsoft's August security updates to protect their systems from potential compromise. The continued targeting of critical infrastructure and defense sectors by advanced persistent threats like Lazarus Group emphasizes the need for robust security practices and timely patching.

AI-written article. Grounded in 13 CVE records listed below.