← back
CVE-2011-1249observed exploitation

CVE-2011-1249

45Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.

ssvc Actepss 8.5%
from disclosure to weapon308 days
Published on NVDJun 16
1st PoC+308d
VulnCheck+14d
exploitation probability
8.5%top 6% of all CVEs
observed exploitation
yesVulnCheck
9 public exploit(s)
The Ancillary Function Driver (AFD) in afd.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Ancillary Function Driver Elevation of Privilege Vulnerability."
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.