CVE-2012-0149: Microsoft Windows Server 2003
High severity, CVSS 7.2. EPSS: 1.5% chance of exploitation in the next 30 days.
afd.sys in the Ancillary Function Driver in Microsoft Windows Server 2003 SP2 does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application, aka "Ancillary Function Driver Elevation of Privilege Vulnerability."
Affected products
- Microsoft Windows Server 2003: any version
Published 2012-02-14. Last modified 2026-06-16.