Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2008-3464
Description:afd.sys in the Ancillary Function Driver (AFD) component in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP1 and SP2 does not properly validate input sent from user mode to the kernel, which allows local users to gain privileges via a crafted application, as demonstrated using crafted pointers and lengths that bypass intended ProbeForRead and ProbeForWrite restrictions, aka "AFD Kernel Overwrite Vulnerability."
Test IDs: 1.3.6.1.4.1.25623.1.0.900223  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2008-3464
BugTraq ID: 31673
http://www.securityfocus.com/bid/31673
Bugtraq: 20081015 Exploit for MS08-066 - AFD.sys kernel memory overwrite. (Google Search)
http://www.securityfocus.com/archive/1/497375/100/0/threaded
Cert/CC Advisory: TA08-288A
http://www.us-cert.gov/cas/techalerts/TA08-288A.html
https://www.exploit-db.com/exploits/6757
HPdes Security Advisory: HPSBST02379
http://marc.info/?l=bugtraq&m=122479227205998&w=2
HPdes Security Advisory: SSRT080143
http://marc.info/?l=bugtraq&m=122479227205998&w=2
http://blogs.technet.com/swi/archive/2008/10/14/ms08-066-how-to-correctly-validate-and-capture-user-mode-data.aspx
Microsoft Security Bulletin: MS08-066
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-066
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5825
http://www.securitytracker.com/id?1021053
http://secunia.com/advisories/32261
http://www.vupen.com/english/advisories/2008/2817
XForce ISS Database: win-afd-privilege-escalation(45578)
https://exchange.xforce.ibmcloud.com/vulnerabilities/45578
XForce ISS Database: win-ms08kb956803-update(45582)
https://exchange.xforce.ibmcloud.com/vulnerabilities/45582




© 1998-2025 E-Soft Inc. All rights reserved.