Microsoft’s August Fixes Cover Exploited Driver and SharePoint Chain

Microsoft’s August 11–12 security updates now pair an actively exploited Windows afd.sys bug, CVE-2026-68820, with Rapid7’s publicly disclosed SharePoint chain that reaches unauthenticated remote code execution through CVE-2026-63520. Microsoft has said the driver flaw is already being used in the wild, and Check Point links it to Lazarus activity. The afd.sys flaw is a use-after-free in Windows Ancillary Function Driver for WinSock: once code is already running on a box, repeated timing hits can lift it to SYSTEM, and Check Point says the group paired that step with a FudModule rootkit to hide from EDR. On SharePoint, one flaw lets an attacker impersonate a chosen user and the second turns that impersonation into code execution as the site’s service account. For Windows defenders and on-prem SharePoint operators, the shared lesson is that a small foothold or no account at all can still become full control through Microsoft plumbing many teams treat as internal. In environments that depend on endpoint telemetry or exposed SharePoint servers, the blast radius is larger than the first access point suggests.

Part of the PlainSec briefing for 2026-08-12

Every edition of this story: Microsoft’s August Fixes Cover Exploited Driver and SharePoint Chain

Sources