Follow ZDNET: Add us as a preferred source on Google. Microsoft continues its onslaught against security vulnerabilities, fixing a whopping 421 bugs in August's Patch Tuesday update. But looking beyond the sheer number, Windows users should install this month's update, as it patches a zero-day flaw that's already been exploited by attackers. Aimed at Windows 11 25H2/24H2, Windows 11 23H2, and Windows 10, the 421 vulnerabilities encompass a range of Microsoft products, including Office, Exchange, Azure, and SharePoint. But it's the Windows patches that clobber the exploited zero-day. In technical jargon, Microsoft titles this flaw a "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability." What that means isn't as important as what it could do. Also: A developer got Word 1.1a from 1990 to run on Windows 11 - try it yourself By exploiting this bug, an attacker could gain system privileges on a Windows 11 or 10 PC without any interaction on the user's part. The person would already need lower-level access to the PC from an initial intrusion. But from there, system privileges would give the attacker the ability to view or delete your files, compromise your security, create user accounts, install malware, and enlist your PC in a botnet. "The primary threat is local privilege escalation," patch management provider Action1 said in a post on the latest update. "An attacker who already has low-privileged access could exploit the vulnerability to gain SYSTEM...
Microsoft fixes 421 bugs and a Windows zero-day in August Patch Tuesday - update ASAP
ZDNet
·Lance Whitney
·Published Aug 12, 2026
·Updated
Affected Software
3 affected components
Microsoft Windows 11>23H2<25H2
Microsoft Windows 10=Windows 10
Microsoft Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability=Aimed at Windows 11 25H2/24H2 and Windows 11 23H2 and Windows 10
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses Microsoft's August Patch Tuesday update, addressing 421 bugs and a critical zero-day vulnerability in Windows.
2
What security implications are discussed in the article?
The article emphasizes the importance of installing the update to protect against a zero-day flaw that could be exploited by attackers.
3
What specific software or products are affected by the August Patch Update?
The update affects Microsoft Windows 10 and Windows 11, along with a vulnerability in the Microsoft Windows Ancillary Function Driver for WinSock.
4
Why is it important for users to update their Windows systems after this Patch Tuesday?
Users are urged to update their systems immediately to mitigate risks from the newly discovered zero-day vulnerability.
5
What type of vulnerabilities does the article mention besides the zero-day flaw?
The article mentions that the Patch Tuesday update addresses a total of 421 security bugs, highlighting a significant range of vulnerabilities.