Junglewise Threat Intelligence

CVE-2021-43226: Microsoft Windows privilege escalation in Common Log File System Driver

CVE-2021-43226 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2025-10-06

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows component responsible for managing system logs. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to install programs, view or delete sensitive data, or create new accounts with full user rights.

Technical details

An elevation of privilege vulnerability exists in the Microsoft Windows Common Log File System (CLFS) driver. The flaw allows a local attacker with low-privileged access to execute code with SYSTEM privileges by exploiting improper memory handling or validation within the driver. This is a local attack vector requiring no user interaction. The vulnerability has been observed being exploited in the wild, and Microsoft has released patches for affected versions of Windows and Windows Server.

Affected products

  • Microsoft Windows 7, 8.1, 10, 11, Server 2008, 2012, 2016, 2019, 2022

Timeline

  • 2021-11-21: disclosed: Initial MSRC advisory publication
  • 2025-10-06: kev added: Added to CISA Known Exploited Vulnerabilities catalog

Related threats