Home / Vulnerabilities / CVE-2011-2005
HIGH SEVERITY
CVE-2011-2005 Microsoft · Ancillary Function Driver (afd.sys)

Microsoft Ancillary Function Driver (afd.sys) Improper Input Validation Vulnerability

Technical Severity

CVSS v3.1 Metrics

HIGH
7.8 / 10
Minimal Risk Critical
Vector Specification
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitation Likelihood

EPSS Prediction

67.09 %
Predictive Probability
Percentile Rank
98.5 th

Documented as more likely to be exploited than 98.5% of known CVEs.

Detection Date

Mar 28, 2022

Remediation Due

Apr 18, 2022

CISA Catalog Active

Threat Analysis

afd.sys in the Ancillary Function Driver in Microsoft Windows does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application.

Remediation Directive

Apply updates per vendor instructions.

External Intelligence