CVE-2011-1249
45Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.
ssvc Actepss 8.5%
from disclosure to weapon308 days
Published on NVDJun 16
1st PoC+308d
VulnCheck+14d
exploitation probability
8.5%top 6% of all CVEs
observed exploitation
yesVulnCheck
9 public exploit(s)
The Ancillary Function Driver (AFD) in afd.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Ancillary Function Driver Elevation of Privilege Vulnerability."
Affected products
n/a · n/apublic PoCs found — 9✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/40564exploitdbwww.exploit-db.com/exploits/18755unverifiedgithubgithub.com/h3x0v3rl0rd/CVE-2011-1249★ 1githubgithub.com/Madusanka99/OHTS★ 0githubgithub.com/appl3b0y/edb-40564-mingw-fix★ 0vulncheckvulncheck.com/xdb/ca5cf30e39ffunverifiedcve_referencewww.exploit-db.com/exploits/40564/unverifiedvulncheckvulncheck.com/xdb/2864639bfda3unverifiedvulncheckvulncheck.com/xdb/e700825c698bunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.