Skip to content
COOEY

EXPOSURES › CVE-2011-2005

CVE-2011-2005

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-28 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2011-2005 ↗
⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatched

Local privilege escalation via improper input validation in Microsoft's Ancillary Function Driver (afd.sys).

A local user can escalate privileges by passing unvalidated user-mode input to kernel mode in afd.sys. DIB orgs must patch this unpatched, actively exploited vulnerability to prevent privilege escalation and potential lateral movement. The flaw is not an RCE but a local privilege escalation, and it was not a zero-day as it was actively exploited in the KEV catalog.

Shame score — Microsoft shipped a known, actively exploited vulnerability for years without a patch, enabling local privilege escalation that attackers leveraged for lateral movement.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

afd.sys in the Ancillary Function Driver in Microsoft Windows does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application.

AFFECTED FEDRAMP PRODUCTS · 4
PRODUCTSTATUS
Azure Commercial Cloud
Microsoft
Authorized
Azure Government (includes Dynamics 365)
Microsoft
Authorized
Microsoft Office 365 GCC High
Microsoft
In Process
Office 365 Multi-Tenant & Supporting Services
Microsoft
Authorized