Executive brief
The Microsoft Windows Common Log File System (CLFS) Driver contains an elevation of privilege vulnerability, likely due to an out-of-bounds write. An attacker who successfully exploits this vulnerability could gain SYSTEM privileges on the affected host.
Affected products
- Microsoft Windows 10 up to (excluding) 10.0.10240.19265, 10.0.14393.5066, 10.0.18363.2212, 10.0.19042.1645, 10.0.19043.1645, 10.0.19044.1645
- Microsoft Windows 11 up to (excluding) 10.0.22000.613
- Microsoft Windows Server 2022 up to (excluding) 10.0.20348.643
- Microsoft Windows 7 SP1
- Microsoft Windows 8.1
- Microsoft Windows Server 2008 SP2, R2 SP1
- Microsoft Windows Server 2012 R2
- Microsoft Windows Server 2016
- Microsoft Windows Server 2019
Timeline
- 2022-04-13: disclosed
- 2022-04-13: patched
- 2022-04-13: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-04-13: exploited