CVE-2008-3464
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 4.0%
exploitation probability
4.0%top 10% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
afd.sys in the Ancillary Function Driver (AFD) component in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP1 and SP2 does not properly validate input sent from user mode to the kernel, which allows local users to gain privileges via a crafted application, as demonstrated using crafted pointers and lengths that bypass intended ProbeForRead and ProbeForWrite restrictions, aka "AFD Kernel Overwrite Vulnerability."
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
cve_reference✓ VexDay Proofwww.exploit-db.com/exploits/6757⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://blogs.technet.com/swi/archive/2008/10/14/ms08-066-how-to-correctly-validate-and-capture-user-mode-data.aspxhttp://marc.info/?l=bugtraq&m=122479227205998&w=2https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-066http://secunia.com/advisories/32261https://exchange.xforce.ibmcloud.com/vulnerabilities/45578https://exchange.xforce.ibmcloud.com/vulnerabilities/45582https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5825https://www.exploit-db.com/exploits/6757http://www.securityfocus.com/archive/1/497375/100/0/threadedhttp://www.securityfocus.com/bid/31673http://www.securitytracker.com/id?1021053http://www.us-cert.gov/cas/techalerts/TA08-288A.html