Microsoft Ancillary Function Driver 'afd.sys' Lets Local Users Gain Elevated Privileges
|
|
SecurityTracker Alert ID: 1021053
|
|
SecurityTracker URL: http://securitytracker.com/id?1021053
|
|
CVE Reference: CVE-2008-3464
(Links to External Site)
|
Date: Oct 14 2008
|
Impact: Execution of arbitrary code via local system, Root access via local system
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Advisory: Microsoft Security Bulletin
|
Version(s): 2003 SP2, XP SP3; and prior service packs
|
Description: A vulnerability was reported in the Windows 2003 and XP Microsoft Ancillary Function Driver. A local user can obtain elevated privileges on the target system.
A local user can invoke the Ancillary Function Driver (afd.sys) to execute arbitrary code on the target system with kernel level privileges.
Fabien Le Mentec of SkyRecon reported this vulnerability.
|
Impact: A local user can obtain kernel level privileges on the target system.
|
Solution: The vendor has issued the following fixes:
Windows XP Service Pack 2 and Windows XP Service Pack 3:
http://www.microsoft.com/downloads/details.aspx?familyid=b16d9dac
-c430-4dd8-a1e5-9a614801f1d9
Windows XP Professional x64 Edition and Windows XP Professional x64 Edition Service Pack 2:
http://www.microsoft.com/downloads/details.
aspx?familyid=5b607efc-c6fb-4079-8478-e4f3262386d3
Windows Server 2003 Service Pack 1 and Windows Server 2003 Service Pack 2:
http://www.microsoft.com/downloads/det
ails.aspx?familyid=ee88ff2d-1b12-4f4c-a081-9f27a6fba074
Windows Server 2003 x64 Edition and Windows Server 2003 x64 Edition Service
Pack 2:
http://www.microsoft.com/downloads/details.aspx?familyid=ab4d94d3-458c-4946-ab7f-03a279629d25
Windows Server 2003
with SP1 for Itanium-based Systems and Windows Server 2003 with SP2 for Itanium-based Systems:
http://www.microsoft.com/downloads/details.aspx?familyid=63234f85-6e5d-4
ef6-b7cf-d1d2c78a5517
A restart is required.
The Microsoft advisory is available at:
http://www.microsoft.com/technet/security/bulletin/ms08-066.mspx
|
Vendor URL: www.microsoft.com/technet/security/bulletin/ms08-066.mspx (Links to External Site)
|
Cause: Input validation error
|
Underlying OS: Windows (2003), Windows (XP)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Tue, 14 Oct 2008 17:05:13 -0400
Subject: http://www.microsoft.com/technet/security/bulletin/ms08-066.mspx
|
Microsoft Security Bulletin MS08-066 – Important: Vulnerability in the Microsoft Ancillary Function D river Could Allow Elevation of Privilege (956803)
CVE-2008-3464
|
|