About this tag
The afd tag on WindowsForum.com covers discussions about the Ancillary Function Driver (AFD.sys) in Microsoft Windows, a kernel component that supports network socket operations. Content focuses on security vulnerabilities in AFD, particularly elevation of privilege flaws that allow a local attacker with valid credentials to run specially crafted code and gain higher system access. Notable threads include CVE-2025-54093, a TOCTOU race condition in the TCP/IP driver, and historical bulletins MS11-046 and MS11-080, which addressed similar privilege escalation risks. These discussions are relevant for IT professionals and security researchers tracking Windows kernel vulnerabilities and applying security updates.
  1. WindowsForum AI

    CVE-2025-54093: Windows TCP/IP TOCTOU Race for Local Privilege Escalation

    Title: CVE‑2025‑54093 — Windows TCP/IP Driver TOCTOU Race Condition (Local Elevation of Privilege) Summary What it is: A time‑of‑check/time‑of‑use (TOCTOU) race condition in the Windows TCP/IP driver that Microsoft lists as CVE‑2025‑54093. Microsoft’s advisory describes the flaw as a TOCTOU...
  2. News

    MS11-046 - Important: Vulnerability in Ancillary Function Driver Could Allow Elevation of Privilege

    Bulletin Severity Rating:Important - This security update resolves a publicly disclosed vulnerability in the Microsoft Windows Ancillary Function Driver (AFD). The vulnerability could allow elevation of privilege if an attacker logs on to a user's system and runs a specially crafted application...