The 2014 Pwnie Winner For Best Privilege Escalation Bug

AFD.sys Dangling Pointer Vulnerability (CVE-2014-1767)

Credit: Sebastian Apelt

Filling in this year for win32k.sys, AFD.sys helped Sebastian win pwn2own 2014. This exploit is a great example of using a kernel exploit to escape the Internet Explorer 11 sandbox on Windows 8.1.

 (CVE-2014-1767)