Sploitus

CVE-2008-3464

3 known exploits for CVE-2008-3464

afd.sys in the Ancillary Function Driver (AFD) component in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP1 and SP2 does not properly validate input sent from user mode to the kernel, which allows local users to gain privileges via a crafted application, as demonstrated using crafted pointers and lengths that bypass intended ProbeForRead and ProbeForWrite restrictions, aka "AFD Kernel Overwrite Vulnerability."

Microsoft Windows 2003 Server
All versions
Microsoft Windows Xp
All versions
Fix
Available
CVSS 2.0
7.2 HIGH
EPSS
4.0% (90th percentile)
Weakness
CWE-264
NVD status
Modified
Published
2008-10-15
CVE-2008-3464 at NVD
Authoritative description, scoring and affected products

3 known exploits for CVE-2008-3464

Proof-of-concept code and exploit modules indexed by Sploitus