EXPOSURES › CVE-2011-2005
CVE-2011-2005
HIGH ⌖ ON CISA KEV · EXPLOITEDLocal privilege escalation via improper input validation in Microsoft's Ancillary Function Driver (afd.sys).
A local user can escalate privileges by passing unvalidated user-mode input to kernel mode in afd.sys. DIB orgs must patch this unpatched, actively exploited vulnerability to prevent privilege escalation and potential lateral movement. The flaw is not an RCE but a local privilege escalation, and it was not a zero-day as it was actively exploited in the KEV catalog.
Shame score — Microsoft shipped a known, actively exploited vulnerability for years without a patch, enabling local privilege escalation that attackers leveraged for lateral movement.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
afd.sys in the Ancillary Function Driver in Microsoft Windows does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application.
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |