Executive brief
A security vulnerability exists in the Windows component responsible for managing system logs. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to install programs, view or delete sensitive data, or create new accounts with full user rights.
Technical details
An elevation of privilege vulnerability exists in the Microsoft Windows Common Log File System (CLFS) driver. The flaw allows a local attacker with low-privileged access to execute code with SYSTEM privileges by exploiting improper memory handling or validation within the driver. This is a local attack vector requiring no user interaction. The vulnerability has been observed being exploited in the wild, and Microsoft has released patches for affected versions of Windows and Windows Server.
Affected products
- Microsoft Windows 7, 8.1, 10, 11, Server 2008, 2012, 2016, 2019, 2022
Timeline
- 2021-11-21: disclosed: Initial MSRC advisory publication
- 2025-10-06: kev added: Added to CISA Known Exploited Vulnerabilities catalog