Microsoft Windows Ancillary Function Driver Elevation of Privilege Vulnerability
8 Mar. 2012
Summary
An elevation of privilege vulnerability exists where the Ancillary Function Driver (afd.sys) improperly validates input passed from user mode to the Windows kernel.
afd.sys in the Ancillary Function Driver in Microsoft Windows Server 2003 SP2 does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application, aka "Ancillary Function Driver Elevation of Privilege Vulnerability."
Vendor Status:
Microsoft has issued an update to correct this vulnerability.