🚨Microsoft Fixes 421 Bugs in June Patch Tuesday
Lazarus Group Exploited a Zero-Day Before Fix
TL;DR
Microsoft patched 421 vulnerabilities in its latest update. Notably, the Lazarus Group exploited one as a zero-day before it was fixed. CVE-2026-68820, tracked and reported by Check Point, could allow SYSTEM-level privileges without user interaction.
Microsoft's June Patch Tuesday addressed 421 bugs, marking a decrease from last month's count. Among these is CVE-2026-68820, a use-after-free flaw in the Windows Ancillary Function Driver for WinSock that North Korea’s Lazarus Group exploited as a zero-day attack early this year. This bug could allow attackers to execute code with SYSTEM-level privileges without user interaction. The patch also includes CVE-2026-62832, an elevation-of-privilege flaw and CVE-2026-62911, an Exchange privilege escalation issue. These updates are crucial for organizations dealing with high-profile cyber threats like the Lazarus Group's Operation Dream Job.

Key Points
Microsoft's June Patch Tuesday addressed 421 vulnerabilities, down from last month's count of around 621.
CVE-2026-68820 is a use-after-free flaw in Windows Ancillary Function Driver for WinSock, exploited by Lazarus Group as a zero-day.
Check Point researchers credited with finding and reporting CVE-2026-68820 observed attackers exploiting this bug early June.
CVE-2026-62832 is an elevation-of-privilege flaw allowing attackers to access or modify another user's data without interaction.
CVE-2026-62911 is one of many Exchange bugs in the release, enabling privilege escalation via authentication bypass.
Why It Matters
If you're a sysadmin managing Windows systems, this update addresses critical vulnerabilities like CVE-2026-68820 and CVE-2026-62911. The former could be exploited by Lazarus Group to gain SYSTEM-level privileges without user interaction. Patching these bugs is crucial for organizations dealing with high-profile cyber threats.
Frequently Asked Questions
Why does this matter?
If you're a sysadmin managing Windows systems, this update addresses critical vulnerabilities like CVE-2026-68820 and CVE-2026-62911. The former could be exploited by Lazarus Group to gain SYSTEM-level privileges without user interaction. Patching these bugs is crucial for organizations dealing with high-profile cyber threats.
What happened?
Microsoft patched 421 vulnerabilities in its latest update. Notably, the Lazarus Group exploited one as a zero-day before it was fixed. CVE-2026-68820, tracked and reported by Check Point, could allow SYSTEM-level privileges without user interaction.
Comments
Be the first to comment
Enjoyed this article?
Get it daily. 7am. Free. Reads in 5 minutes.
Join 2,900 builders reading daily.