Description
A vulnerability exists in the Windows Ancillary Function Driver for Winsock (`afd.sys`) can be leveraged by an attacker to escalate privileges to those of NT AUTHORITY\SYSTEM. Due to a flaw in `AfdNotifyRemoveIoCompletion`, it is possible to create an arbitrary kernel Write-Where primitive, which can be used to manipulate internal I/O ring structures and achieve local privilege escalation.
This exploit only supports Windows 11 22H2 up to build 22621.963 (patched in January 2023 updates).
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use exploit/windows/local/cve/2023_21768_afd_lpemsf undefined(2023_21768_afd_lpe) > show actions ...actions...msf undefined(2023_21768_afd_lpe) > set ACTION < action-name >msf undefined(2023_21768_afd_lpe) > show options ...show and set options...msf undefined(2023_21768_afd_lpe) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub