CVE-2011-1249 is an improper input-validation vulnerability in the Microsoft Windows Ancillary Function Driver (AFD), implemented in afd.sys. AFD does not properly validate user-mode input on affected Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, and Windows 7 versions. A local user can exploit the flaw by running a crafted application to elevate privileges.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository is a small standalone local privilege-escalation exploit for MS11-046 / CVE-2011-1249 affecting the Windows AFD.sys driver. It contains only two files: a README describing the vulnerability, MinGW-related fixes, build instructions, and usage examples; and a single C source file, ms11-046.c, which implements the exploit logic. The code is not part of a larger framework. The exploit targets vulnerable 32-bit Windows systems and requires prior local code execution as a low-privileged user. Its core capability is elevating privileges to NT AUTHORITY\SYSTEM by abusing the AFD driver through a crafted DeviceIoControl request. After kernel execution is achieved, it triggers execution through the HalDispatchTable/NtQueryIntervalProfile technique and then runs a post-exploitation command in SYSTEM context. A notable modification in this fork is operational usability rather than exploit-chain changes: it fixes MinGW compilation issues by replacing a generic FARPROC declaration for ZwQuerySystemInformation with a typed function pointer, fixes a dangling-pointer bug in patch-list handling, and adds argv[1]-based custom command execution. As a result, the exploit can either spawn cmd.exe as SYSTEM or execute arbitrary commands/payload paths supplied by the operator, such as adding a user or launching a custom executable. Fingerprintable artifacts are mostly local rather than network-based. The main target endpoint is the Windows device path \\.\AFD\Endpoint, and the exploit uses IOCTL 0x00012007 to reach the vulnerable code path. There are no hardcoded C2 servers, remote URLs, or exfiltration endpoints in the exploit logic itself. The remaining URLs in the repository are documentation and patch-reference links. Overall, this is a real, functional local kernel LPE proof-of-concept with a basic but practical payload execution mechanism, making it operational rather than merely demonstrative.
This repository contains a local privilege escalation exploit for Microsoft Windows (CVE-2011-1249, MS11-046), targeting a vulnerability in the AFD (Ancillary Function Driver) kernel driver (afd.sys). The exploit is implemented in C (file: 40564.c) and is designed to be compiled for Windows x86 systems using MinGW. The exploit requires local access to a vulnerable, unpatched Windows system (XP, Server 2003, Vista, Server 2008, or Windows 7 x86). Upon execution, it leverages a flaw in afd.sys to elevate the current user's privileges to SYSTEM and spawns a SYSTEM-level command shell (cmd.exe). The README provides compilation instructions and screenshots of successful exploitation. No network endpoints are involved; the attack vector is strictly local. The exploit is operational and provides a working SYSTEM shell if the target is vulnerable.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.