← Back to browse · API

CVE-2011-2005

Severity
HIGH
CVSS
7.8
EPSS
0.31761
Risk score
67.32
CISA KEV
Yes
PoC
No
Published
2011-10-12
Modified
2025-10-22
First seen
2026-08-07
Aliases
EUVD-2011-1999, GHSA-8Q8W-V8PG-496J
Products
Microsoft:Ancillary Function Driver (afd.sys), n/a:n/a n/a
Sources
cisa.gov CVE-2011-2005
euvd EUVD-2011-1999

Description

afd.sys in the Ancillary Function Driver in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application, aka "Ancillary Function Driver Elevation of Privilege Vulnerability."

References