7.2
CVSSv2

CVE-2011-2005

Published: 12/10/2011 Updated: 26/02/2019
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 730
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

afd.sys in the Ancillary Function Driver in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application, aka "Ancillary Function Driver Elevation of Privilege Vulnerability."

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft windows xp -

microsoft windows 2003 server

microsoft windows xp

microsoft windows server 2003

Exploits

MS11-080 privilege escalation exploit that leverages the fact that afdsys does not properly validate user-mode input passed to kernel-mode ...
## # This file is part of the Metasploit Framework and may be subject to # redistribution and commercial restrictions Please see the Metasploit # web site for more information on licensing and terms of use # metasploitcom/ ## require 'msf/core' require 'rex' require 'msf/core/post/common' require 'msf/core/post/windows/priv' class Met ...
################################################################################ ######### MS11-080 - CVE-2011-2005 Afdsys Privilege Escalation Exploit ######## ######### Author: ryujin@offseccom - Matteo Memelli ######## ######### Spaghetti & Pwnsauce ######## ######### ...

Recent Articles

Carders cash out hundreds of millions before USA adopts EMV
The Register • Darren Pauli • 22 Apr 2016

Stolen card values on the way down ahead of chip card debut

A hacker group has stolen some 10 million credit cards, putting itself in a position to score US$400 million (£279 million, A$516 million) by infecting 2000 payment terminals with the Trinity point of sales malware. Security firm FireEye and subsidiaries iSIGHT Partners and Mandiant examined the "Fin6" group last year after it was found plundering millions of cards. The first two firms now say the cards stolen from hospitality and retails firms have earned the hacking group hundreds of millions...