PT-2011-3544 · Microsoft · Ancillary Function Driver+1

Bo Zhou

·

Published

2011-10-11

·

Updated

2025-04-04

·

CVE-2011-2005

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Ancillary Function Driver (afd.sys) versions prior to the fixed version
Description The issue is related to improper input validation in the Ancillary Function Driver, allowing local users to gain privileges via a crafted application. This vulnerability enables an attacker to execute code with elevated privileges, potentially leading to full control over the system, including the ability to install programs, view, modify, and delete data, and create new accounts with full administrator rights.
Recommendations For Microsoft Ancillary Function Driver (afd.sys), update to a version that includes the fix for this issue to prevent exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Related Identifiers

CVE-2011-2005

Affected Products

Ancillary Function Driver
Windows