Junglewise Threat Intelligence

CVE-2011-2005: Microsoft Ancillary Function Driver (afd.sys) Improper Input Validation Vulnerability

CVE-2011-2005 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-03-28

Technologies: Microsoft Windows Server 2003, Microsoft Windows XP. Vendors: Microsoft.

Executive brief

The Ancillary Function Driver (afd.sys) in Microsoft Windows fails to properly validate user-mode input passed to kernel mode. This flaw allows a local attacker to gain elevated privileges by executing a specially crafted application.

Affected products

  • Microsoft Windows XP SP2, SP3
  • Microsoft Windows Server 2003 SP2

Timeline

  • 2011-10-11: disclosed: NVD Published Date
  • 2011-10-11: patched: Microsoft released security bulletin MS11-080
  • 2022-03-28: kev added: Added to CISA Known Exploited Vulnerabilities Catalog