CVE-2023-28218 is a local privilege escalation vulnerability in the Windows Ancillary Function Driver for WinSock (afd.sys). The flaw is in the Fast I/O handling path of AfdFastIoDeviceControl when processing the AfdSendMessage IOCTL. The vulnerable logic parses a user-supplied CMSG buffer, computes a kernel allocation size, and then copies attacker-controlled chunks into kernel memory. In AfdCopyCMSGBuffer, an integer overflow can occur during 8-byte alignment of a user-controlled chunk size. Under crafted values, the aligned size can wrap in a way that defeats bounds checking, leading to a heap buffer overflow in kernel memory during the subsequent copy operation. The issue is further exploitable because the code path performs a double fetch of attacker-controlled data between the size-computation stage and the copy stage, allowing the chunk size to be changed after allocation but before copying. This combination enables controlled corruption of adjacent kernel heap objects and can be leveraged to modify sensitive kernel state for elevation of privilege.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a full exploit and a minimal proof-of-concept (POC) for CVE-2023-28218, a local privilege escalation vulnerability in the Windows kernel (AFD.sys driver). The exploit leverages a double-fetch and integer overflow bug in the Afd!AfdComputeCMSGLength and Afd!AfdCopyCMSGBuffer functions, allowing a local attacker to overflow a non-paged pool and corrupt adjacent named pipe objects. The main exploit (POC/POC/POC.cpp) performs heap spraying with named pipes, creates holes, and uses a race condition to overwrite the process token, ultimately spawning a SYSTEM shell. The minimal POC (minimalPOC/Project1/minimal.cpp) demonstrates the core race condition and DeviceIoControl trigger. The exploit targets a wide range of unpatched Windows versions (see README for details). The attack vector is local, requiring code execution on the target. Notable endpoints include the named pipe (\\.\pipe\lmaolmaolmao), the AFD.sys driver, and a socket bound to 127.0.0.1:135. The exploit is operational, providing a SYSTEM shell if successful, but may cause system instability or crashes due to heap corruption.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A local privilege escalation vulnerability in Microsoft Windows, allowing attackers to gain elevated privileges on a compromised system.
A Windows kernel afd.sys vulnerability in AfdFastIoDeviceControl/AfdCopyCMSGBuffer involving integer overflow during CMSG buffer handling, enabling a heap overflow and local privilege escalation.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.